CVE-2024-53636
An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.
An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackers to execute arbitrary code via ../ in the filePath parameter.
MEDIUM · CVSS 6.4
EPSS 0.02919
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0