CVE-2021-44087
Critical · CVSS 9.8Sourcecodester Attendance and Payroll System — Unauthenticated File Upload Remote Code Execution (RCE)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- NVD-CWE-noinfo
Description
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload.
Search profile — drives PoC discovery
Symbols photo uploadfile uploadPHP file uploadapsystemoretnom23
Keywords CVE-2021-44087Attendance and Payroll SystemSourcecodesterRCEfile uploadPHP uploadunauthenticatedapsystemexploit-db 50801
Versions: v1.0
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z