College Management System v1.0 - Authenticated remote code execution.An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload.php file that contains malicious code via student.php file.
- https://www.gov.il/en/Departments/faq/cve_advisories
No PoCs found on GitHub currently.