
Proof-of-concept exploit for CVE-2025-46157: Remote code execution via insecure file upload in Timetrax V1 Attendance module, with EfsPotato-based privilege escalation to SYSTEM.
A critical vulnerability was discovered in Timetrax V1 (2025) that allows authenticated users to bypass file upload restrictions and achieve remote code execution (RCE). The issue exists in the Leave Request form of the Attendance module, where weak server-side validation permits the upload of malicious .asp web shells via modified requests.
Further exploitation allows privilege escalation to SYSTEM using the EfsPotato technique by abusing the SeImpersonatePrivilege.
.txt to .aspSeImpersonatePrivilegeBase Score: 9.9 (Critical)
Vector String: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
.txt file, intercept the HTTP request using Burp Suite..txt to .asp.SeImpersonatePrivilege.SeImpersonatePrivilege to required accounts onlyThis repository is part of responsible disclosure and educational purposes only. Always follow ethical guidelines and coordinated disclosure policies.