Description
A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the file technical_staff_pic.php. Such manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Problem types
Product status
Timeline
| 2025-12-13: | Advisory disclosed |
| 2025-12-13: | VulDB entry created |
| 2025-12-13: | VulDB entry last update |
Credits
Yohane-Mashiro (VulDB User)
References
vuldb.com/?id.336375 (VDB-336375 | code-projects Computer Laboratory System technical_staff_pic.php unrestricted upload)
vuldb.com/?ctiid.336375 (VDB-336375 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.707866 (Submit #707866 | ode-projects.org Computer Laboratory System In PHP With Source Code 1.0 Incomplete Identification of Uploaded File Variables)
github.com/Yohane-Mashiro/cve/blob/main/upload 4.md
code-projects.org/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.