
Exploit about School Management System 7.1 (Authenticated RCE)
Publication date: 2025-10-17
Author / Discoverer: Lebas Vivien
Status: Reserved
CVE: CVE-2025-60500 (reserved)
An insecure file upload / logic flaw in QDocs Smart School — School Management System 7.1 allows authenticated users with roles such as accountant, admin, or superadmin to bypass file-type restrictions in the media upload feature by abusing the alternative YouTube URL option. This flaw permits an attacker to cause arbitrary PHP files to be stored in a web-accessible directory, enabling remote code execution when the uploaded file is accessed.
Affected product: Smart School : School Management System 7.1 (QDocs)
Vendor confirmed: Yes
.php extension in a web-accessible directory.accountant, admin or superadmin..php (the server-side checks/filters attempt to block PHP uploads through the regular file-type validation)..php file via the returned URL to trigger code execution (if the file contains executable PHP code).Vendor-side fixes (recommended):
chmod to remove execute permission; configure web server not to execute PHP from upload directories).Workarounds for administrators:
.php in the /uploads/... directory.https://smart-school.in/demo