CVE-2021-4462

Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; uploaded files can be executed because the application does not perform proper server-side validation. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.
Configurations

Configuration 1 (hide)

cpe:2.3:a:skittles:employee_records_system:1.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-11-10 23:15

Updated : 2025-11-24 12:57


NVD link : CVE-2021-4462

Mitre link : CVE-2021-4462

CVE.ORG link : CVE-2021-4462


JSON object : View

Products Affected

skittles

  • employee_records_system
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type