Critical severity9.8NVD Advisory· Published Jan 18, 2022· Updated Jun 17, 2026
CVE-2021-46013
CVE-2021-46013
Description
An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this vulnerability to enable remote code execution on the affected web server. Once a php webshell containing "<?php system($_GET["cmd"]); ?>" gets uploaded it is saved into /uploads/exam_question/ directory, and is accessible by all users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:free_school_management_software_project:free_school_management_software:1.0:*:*:*:*:*:*:*
- Sourcecodester/Free school management softwaredescription
- Range: = 1.0
Patches
Vulnerability mechanics
References
1- www.exploit-db.com/exploits/50587nvdExploitThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.