Executive brief
A student management web application accepts profile image uploads without validating file types, allowing attackers with basic user accounts to upload arbitrary files including scripts. If the web server executes PHP files in the upload directory, an attacker can gain remote code execution and full control of the server. Even without PHP execution, attackers can host malicious content or conduct phishing attacks.
Technical details
The vulnerability is an unrestricted file upload flaw in the student_profile_pic.php component's storeProfileImage function. The application accepts file uploads via the choose_file parameter without validating file type, MIME type, file extension, or file contents. The server uses the original user-supplied filename directly when storing the upload in a web-accessible directory (../../asset/upload/), then passes it to move_uploaded_file(). An authenticated attacker (any student or staff user) can upload a PHP file or other executable content that will be stored and executed by the web server. The vulnerability requires network access and valid credentials but no user interaction beyond file upload. Public disclosure and exploitation code are available. No patch information has been released as the vendor did not respond to early disclosure attempts.
Affected products
- imranrisal-dev Student-Management-System commit 18ea7904c339e0c7b0234724a79c939ce6191def and a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c
Timeline
- 2026-06-16: disclosed: Public disclosure on GitHub with proof-of-concept
- 2026-08-05: advisory: CVE-2026-18927 published
- 2026: other: Vendor contacted early but did not respond