A vulnerability classified as critical has been found in PHPGurukul eLearning System 1.0. Affected is an unknown function of the file /user/index.php of the component Image Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
History

Mon, 24 Mar 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Janobe
Janobe elearning System
CPEs cpe:2.3:a:janobe:elearning_system:1.0:*:*:*:*:*:*:*
Vendors & Products Janobe
Janobe elearning System

Mon, 24 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Mar 2025 06:15:00 +0000

Type Values Removed Values Added
Description A vulnerability classified as critical has been found in PHPGurukul eLearning System 1.0. Affected is an unknown function of the file /user/index.php of the component Image Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Title PHPGurukul eLearning System Image index.php unrestricted upload
Weaknesses CWE-284
CWE-434
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-03-24T06:00:12.375Z

Updated: 2025-03-24T12:22:21.869Z

Reserved: 2025-03-23T09:25:05.701Z

Link: CVE-2025-2687

cve-icon Vulnrichment

Updated: 2025-03-24T12:22:12.774Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-24T06:15:13.397

Modified: 2025-03-24T17:25:06.777

Link: CVE-2025-2687

cve-icon Redhat

No data.