CVE-2018-18793: School Event Management System Project School Event Management System

Critical severity, CVSS 9.8. EPSS: 9.5% chance of exploitation in the next 30 days.

School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.

Affected products

Published 2018-11-16. Last modified 2026-06-17.