Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 22 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:sanjay1313:visitor_management_system:1.0:*:*:*:*:*:*:* |
Wed, 22 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sanjay1313
Sanjay1313 visitor Management System |
|
| Vendors & Products |
Sanjay1313
Sanjay1313 visitor Management System |
Wed, 22 Apr 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unrestricted File Upload Lacking Validation in Visitor Management System 1.0 |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unrestricted File Upload Lacking Validation in Visitor Management System 1.0 | |
| Weaknesses | CWE-434 | |
| Metrics |
cvssV3_1
|
Tue, 21 Apr 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Visitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php and vms/php/update_1.php. The move_uploaded_file() function is called without any MIME type, extension, or content validation, allowing an authenticated admin to upload a PHP webshell and achieve Remote Code Execution on the server. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-21T18:25:24.762Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-37748
Updated: 2026-04-21T18:24:59.959Z
Status : Analyzed
Published: 2026-04-21T16:16:20.113
Modified: 2026-04-22T16:02:05.980
Link: CVE-2026-37748
No data.
OpenCVE Enrichment
Updated: 2026-04-22T11:47:04Z