CVE-2021-4462
Employee Records System v1.0 Arbitrary File Upload RCE
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; uploaded files can be executed because the application does not perform proper server-side validation. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.
| CWE | CWE-434 |
| Vendor | employee records system |
| Product | employee records system |
| Published | Nov 10, 2025 |
| Last Updated | Apr 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for employee records system employee records system
Be the first to know when new unknown vulnerabilities affecting employee records system employee records system are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Employee Records System / Employee Records System
1.0
References
Credits
sml