Metrics
Affected Vendors & Products
Mon, 24 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Skittles
Skittles employee Records System |
|
| CPEs | cpe:2.3:a:skittles:employee_records_system:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Skittles
Skittles employee Records System |
|
| Metrics |
cvssV3_1
|
Fri, 21 Nov 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:employee_records_system_project:employee_records_system:1.0:*:*:*:*:*:*:* |
Thu, 20 Nov 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; uploaded files can be executed because the application does not perform proper server-side validation. | Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; uploaded files can be executed because the application does not perform proper server-side validation. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC. |
Wed, 12 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Employee Records System Project
Employee Records System Project employee Records System |
|
| Vendors & Products |
Employee Records System Project
Employee Records System Project employee Records System |
Mon, 10 Nov 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; uploaded files can be executed because the application does not perform proper server-side validation. | |
| Title | Employee Records System v1.0 Arbitrary File Upload RCE | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-21T14:35:46.468Z
Reserved: 2025-11-07T20:14:57.048Z
Link: CVE-2021-4462
Updated: 2025-11-12T17:33:48.850Z
Status : Analyzed
Published: 2025-11-10T23:15:40.967
Modified: 2025-11-24T12:57:17.830
Link: CVE-2021-4462
No data.