Impact
The flaw in the upload_files.php script allows attackers to upload any file type without restriction.
Affected Systems
SourceCodester Syllabus-Aligned Learning Management and Examination System version 1.0 in an unknown function of upload_files.php.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk level. The exploit has been released to the public, so attackers can target the upload endpoint remotely through the web interface. Although the EPSS score is < 1% and the vulnerability is not listed in the KEV catalog, the availability of the exploit means that anyone who can access the upload functionality could potentially upload arbitrary files.
OpenCVE Enrichment