Employee Records System v1.0 Arbitrary File Upload RCE
Vulnerability Description
Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; uploaded files can be executed because the application does not perform proper server-side validation. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-4462
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- sml
Affected Vendor
Employee Records System
View all reports →