CVE-2018-6860 describes an arbitrary file upload and remote code execution vulnerability in PHP Scripts Mall Schools Alert Management Script version 2.0.2, specifically exploitable through the profile picture upload function. This vulnerability carries a high CVSS score of 8.8, indicating a critical risk due to its low attack complexity, requiring only low privileges, and potential for complete compromise of confidentiality, integrity, and availability. While no public exploits (Metasploit, Nuclei, ExploitDB) are currently available and there is no evidence of active exploitation, its high FAUCET Risk Score of 73/100 suggests a significant threat. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.2CPE matchmatch criteria | cpe:2.3:a:schools_alert_management_script_project:schools_alert_management_script:2.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.