CVE-2025-60500

QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in the media upload feature by abusing the alternate YouTube URL option. This logic flaw permits uploading of arbitrary PHP files, which are stored in a web-accessible directory.
References
Link Resource
https://github.com/H4zaz/CVE-2025-60500 Exploit Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:qdocs:smart_school:7.1.0:*:*:*:*:*:*:*

History

17 Nov 2025, 12:46

Type Values Removed Values Added
First Time Qdocs
Qdocs smart School
CPE cpe:2.3:a:qdocs:smart_school:7.1.0:*:*:*:*:*:*:*
References () https://github.com/H4zaz/CVE-2025-60500 - () https://github.com/H4zaz/CVE-2025-60500 - Exploit, Mitigation, Third Party Advisory

21 Oct 2025, 19:21

Type Values Removed Values Added
CWE CWE-434
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

21 Oct 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-21 17:15

Updated : 2025-11-17 12:46


NVD link : CVE-2025-60500

Mitre link : CVE-2025-60500

CVE.ORG link : CVE-2025-60500


JSON object : View

Products Affected

qdocs

  • smart_school
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type