{"api_version":"1","generated_at":"2026-07-23T14:24:39+00:00","cve":"CVE-2020-28072","urls":{"html":"https://cve.report/CVE-2020-28072","api":"https://cve.report/api/cve/CVE-2020-28072.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-28072","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-28072"},"summary":{"title":"CVE-2020-28072","description":"A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in the gallery.php page and executing it on the server reaching the RCE.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-12-15 21:15:00","updated_at":"2020-12-17 20:52:00"},"problem_types":["CWE-434"],"metrics":[],"references":[{"url":"http://packetstormsecurity.com/files/160508/Alumni-Management-System-1.0-Shell-Upload.html","name":"http://packetstormsecurity.com/files/160508/Alumni-Management-System-1.0-Shell-Upload.html","refsource":"MISC","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Alumni Management System 1.0 Shell Upload ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-28072","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-28072","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"28072","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"alumni_management_system_project","cpe5":"alumni_management_system","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"28072","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"alumni_management_system_project","cpe5":"alumni_management_system","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-28072","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in the gallery.php page and executing it on the server reaching the RCE."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"http://packetstormsecurity.com/files/160508/Alumni-Management-System-1.0-Shell-Upload.html","url":"http://packetstormsecurity.com/files/160508/Alumni-Management-System-1.0-Shell-Upload.html"}]}},"nvd":{"publishedDate":"2020-12-15 21:15:00","lastModifiedDate":"2020-12-17 20:52:00","problem_types":["CWE-434"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:alumni_management_system_project:alumni_management_system:1.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"28072","Ordinal":"189808","Title":"CVE-2020-28072","CVE":"CVE-2020-28072","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"28072","Ordinal":"1","NoteData":"A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in the gallery.php page and executing it on the server reaching the RCE.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"28072","Ordinal":"2","NoteData":"2020-12-15","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"28072","Ordinal":"3","NoteData":"2020-12-15","Type":"Other","Title":"Modified"}]}}}