CVE-2019-20183: Employee Records System Project Employee Records System
High severity, CVSS 7.2. EPSS: 7.8% chance of exploitation in the next 30 days.
uploadimage.php in Employee Records System 1.0 allows upload and execution of arbitrary PHP code because file-extension validation is only on the client side. The attacker can modify global.js to allow the .php extension.
Affected products
- Employee Records System Project Employee Records System: version 1.0 only
Published 2020-01-09. Last modified 2026-06-17.