Impact
The flaw in the admin_pic.php module allows an attacker to upload arbitrary files without validation. Based on the description, it is inferred that an attacker can execute code on the server if a malicious script is uploaded, giving full control. This weakness falls under missing authorization and unrestricted input categories.
Affected Systems
The vulnerability exists in the code-projects Online Examination System version 1.0. The issue originates from the admin_pic.php component of this product.
Risk and Exploitability
The CVSS score of 5.3 reflects medium severity, but the EPSS score of less than 1% indicates low exploitation probability in the wild. The exploit is accessible from remote, and no protections such as authentication or file type checks are present. Even though not listed in KEV, it is inferred that remote code execution is possible if malicious files are uploaded, warranting prompt remediation.
OpenCVE Enrichment