What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in rudrainn Training – Courses training allows Upload a Web Shell to a Web Server.This issue affects Training – Courses: from n/a through <= 2.0.1.
Explanation of Vulnerability in Simple Terms
02Summary
Training – Courses versions 2.0.1 and earlier allow authenticated users to upload files without restriction. An attacker with low-level account access can upload malicious files to compromise the site's integrity, confidentiality, and availability. The vulnerability affects the entire system due to scope change.
What an attacker can do
03Attacker Capabilities
Upload malicious files to the site and execute arbitrary code or access sensitive data.
Potential impact on your site
04Site Impact
Compromised site integrity, data theft, and potential complete system takeover by any authenticated user.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the site.
Key dates
06Disclosure timeline
November 4, 2024
CVE published
May 11, 2026
Record updated