CVE-2021-4462
Gravedad CVSS v4.0:
CRÍTICA
Tipo:
CWE-434
Subida sin restricciones de ficheros de tipos peligrosos
Fecha de publicación:
10/11/2025
Última modificación:
12/11/2025
Descripción
*** Pendiente de traducción *** Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; uploaded files can be executed because the application does not perform proper server-side validation.
Impacto
Puntuación base 4.0
9.30
Gravedad 4.0
CRÍTICA



