🔐 CVE Alert

CVE-2021-4462

UNKNOWN 0.0

Employee Records System v1.0 Arbitrary File Upload RCE

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; uploaded files can be executed because the application does not perform proper server-side validation. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.

CWE CWE-434
Vendor employee records system
Product employee records system
Published Nov 10, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for employee records system employee records system

Be the first to know when new unknown vulnerabilities affecting employee records system employee records system are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Employee Records System / Employee Records System
1.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
sourcecodester.com: https://www.sourcecodester.com/php/11393/employee-records-system.html exploit-db.com: https://www.exploit-db.com/exploits/49596 vulncheck.com: https://www.vulncheck.com/advisories/employees-records-system-arbitrary-file-upload-rce

Credits

sml