Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 24 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Skittles
Skittles employee Records System |
|
| CPEs | cpe:2.3:a:skittles:employee_records_system:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Skittles
Skittles employee Records System |
|
| Metrics |
cvssV3_1
|
Fri, 21 Nov 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:employee_records_system_project:employee_records_system:1.0:*:*:*:*:*:*:* |
Thu, 20 Nov 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; uploaded files can be executed because the application does not perform proper server-side validation. | Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; uploaded files can be executed because the application does not perform proper server-side validation. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC. |
Wed, 12 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Employee Records System Project
Employee Records System Project employee Records System |
|
| Vendors & Products |
Employee Records System Project
Employee Records System Project employee Records System |
Mon, 10 Nov 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; uploaded files can be executed because the application does not perform proper server-side validation. | |
| Title | Employee Records System v1.0 Arbitrary File Upload RCE | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-21T14:35:46.468Z
Reserved: 2025-11-07T20:14:57.048Z
Link: CVE-2021-4462
Updated: 2025-11-12T17:33:48.850Z
Status : Analyzed
Published: 2025-11-10T23:15:40.967
Modified: 2025-11-24T12:57:17.830
Link: CVE-2021-4462
No data.
OpenCVE Enrichment
Updated: 2025-11-12T12:48:12Z