module
Prison Management System 1.0 Authenticated RCE via Unrestricted File Upload
| Disclosed | Created |
|---|---|
| Oct 28, 2024 | Jan 8, 2026 |
Disclosed
Oct 28, 2024
Created
Jan 8, 2026
Description
This module exploits an unrestricted file upload vulnerability in Prison Management System 1.0.
An authenticated user can upload a PHP file with arbitrary content by abusing the avatar upload
functionality in the add-admin.php endpoint. The application fails to properly validate the
uploaded file type, allowing an attacker to upload a PHP webshell.
An authenticated user can upload a PHP file with arbitrary content by abusing the avatar upload
functionality in the add-admin.php endpoint. The application fails to properly validate the
uploaded file type, allowing an attacker to upload a PHP webshell.
Author
Alexandru Ionut Raducu
Platform
Linux,PHP,Unix
Architectures
php, cmd, x64, x86
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.