CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2021-44087

Critical · CVSS 9.8

Sourcecodester Attendance and Payroll System — Unauthenticated File Upload Remote Code Execution (RCE)

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
NVD-CWE-noinfo

Description

A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload.

Search profile — drives PoC discovery

Symbols photo uploadfile uploadPHP file uploadapsystemoretnom23
Keywords CVE-2021-44087Attendance and Payroll SystemSourcecodesterRCEfile uploadPHP uploadunauthenticatedapsystemexploit-db 50801
Versions: v1.0

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z