CVE-2021-25200
Published Jul 30, 2021Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to \lms\student_avatar.php.
Vendor/product archive
2 CVEs tagged to learning_management_system_project / learning_management_system — 1 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.
Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to \lms\student_avatar.php.
SQL injection vulnerability in Learning Management System v 1.0 allows remote attackers to execute arbitrary SQL statements through the id parameter to obtain sensitive database i…