Junglewise Threat Intelligence

CVE-2026-5472: ProjectsAndPrograms School Management System unrestricted upload in Profile Picture Handler

CVE-2026-5472 · Severity: medium · CVSS 6.3 · Published 2026-04-03

Technologies: ProjectsAndPrograms School Management System.

Executive brief

A security vulnerability exists in the ProjectsAndPrograms School Management System, a platform used for managing educational institutions. An authenticated user, such as a teacher or administrator, can upload malicious files through the profile picture update feature. This could allow an attacker to take full control of the server, potentially leading to the theft of student data or a complete shutdown of school operations.

Technical details

An unrestricted file upload vulnerability exists in the Profile Picture Handler component of the ProjectsAndPrograms School Management System. The flaw is located in the handling of the 'File' argument within /admin_panel/settings.php (specifically involving assets/updateProfilePic.php). Authenticated users with Admin or Teacher privileges can bypass file type restrictions to upload arbitrary PHP scripts. By accessing the uploaded file via its direct path on the server, an attacker can achieve Remote Code Execution (RCE). A proof-of-concept exploit has been publicly disclosed.

Affected products

  • ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59

Timeline

  • 2026-04-03: disclosed
  • 2026-04-03: advisory

References