uploadimage.php in Employee Records System 1.0 allows upload and execution of arbitrary PHP code because file-extension validation is only on the client side. The attacker can modify global.js to allow the .php extension.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.