Ventem|e-School – Arbitrary File Upload

CVE Details

Basic Information

Title Ventem|e-School – Arbitrary File Upload
Type cve
Published 2025-07-30T02:54:07.404Z
Modified 2025-07-30T02:54:07.404Z

Product Information

Vendor Ventem
Product e-School
Version 0

CVSS Information

Base Score 8.8 (HIGH)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Analysis

AI Description Ventem’s e-School platform is vulnerable to arbitrary file uploads, allowing attackers to execute malicious code remotely without authentication.
AI Severity High
AI Vendor Ventem
AI Product e-School
AI Version 0

Affected Products

  • Ventem e-School 0

Additional Information

CWE List CWE-434
Source twcert

Description

The e-School from Ventem has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.