QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in the media upload feature by abusing the alternate YouTube URL option. This logic flaw permits uploading of arbitrary PHP files, which are stored in a web-accessible directory.
References
| Link | Resource |
|---|---|
| https://github.com/H4zaz/CVE-2025-60500 | Exploit Mitigation Third Party Advisory |
Configurations
History
17 Nov 2025, 12:46
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:qdocs:smart_school:7.1.0:*:*:*:*:*:*:* | |
| References | () https://github.com/H4zaz/CVE-2025-60500 - Exploit, Mitigation, Third Party Advisory | |
| First Time |
Qdocs smart School
Qdocs |
Information
Published : 2025-10-21 17:15
Updated : 2025-11-17 12:46
NVD link : CVE-2025-60500
Mitre link : CVE-2025-60500
CVE.ORG link : CVE-2025-60500
JSON object : View
Products Affected
qdocs
- smart_school
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
