CVE-2025-60500

QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in the media upload feature by abusing the alternate YouTube URL option. This logic flaw permits uploading of arbitrary PHP files, which are stored in a web-accessible directory.
References
Link Resource
https://github.com/H4zaz/CVE-2025-60500 Exploit Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:qdocs:smart_school:7.1.0:*:*:*:*:*:*:*

History

17 Nov 2025, 12:46

Type Values Removed Values Added
CPE cpe:2.3:a:qdocs:smart_school:7.1.0:*:*:*:*:*:*:*
References () https://github.com/H4zaz/CVE-2025-60500 - () https://github.com/H4zaz/CVE-2025-60500 - Exploit, Mitigation, Third Party Advisory
First Time Qdocs smart School
Qdocs

Information

Published : 2025-10-21 17:15

Updated : 2025-11-17 12:46


NVD link : CVE-2025-60500

Mitre link : CVE-2025-60500

CVE.ORG link : CVE-2025-60500


JSON object : View

Products Affected

qdocs

  • smart_school
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type