216.73.217.22

CVE-2021-4462

· Published 10/11/2025 23:15 · Modified 24/11/2025 12:57

Labels: CVE-2021-4462 2025-11-10CVE-2021-4462CWE-434[email protected]

Essential information

Published
10/11/2025 23:15
Modified
24/11/2025 12:57
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; uploaded files can be executed because the application does not perform proper server-side validation. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
skittles / employee records system cpe:2.3:a:skittles:employee_records_system:1.0:*:*:*:*:*:*:*

References