CVE-2024-53636

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/04/2025
Last modified:
29/01/2026

Description

An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackers to execute arbitrary code via ../ in the filePath parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:academiaerp:student_information_system:eagler-1.0.118:*:*:*:*:*:*:*