Description
A security flaw has been discovered in code-projects Employee Profile Management System 1.0. Impacted is an unknown function of the file /profiling/add_file_query.php. The manipulation of the argument per_file results in unrestricted upload. The attack may be launched remotely. The exploit has been released to the public and may be exploited.
Problem types
Product status
Timeline
| 2025-12-06: | Advisory disclosed |
| 2025-12-06: | VulDB entry created |
| 2025-12-06: | VulDB entry last update |
Credits
xuanyuesanshi (VulDB User)
References
vuldb.com/?id.334615 (VDB-334615 | code-projects Employee Profile Management System add_file_query.php unrestricted upload)
vuldb.com/?ctiid.334615 (VDB-334615 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.699247 (Submit #699247 | code-projects Employee Profile Management System published November 15, 2025 Unrestricted Upload)
github.com/shenxianyuguitian/employee-management-UFU
code-projects.org/