Description
A vulnerability has been found in code-projects Student File Management System 1.0. The affected element is an unknown function of the file /download.php of the component File Download Handler. The manipulation of the argument store_id leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Problem types
Incorrect Privilege Assignment
Product status
Timeline
| 2025-12-28: | Advisory disclosed |
| 2025-12-28: | VulDB entry created |
| 2025-12-28: | VulDB entry last update |
Credits
Mountain Ghost (VulDB User)
References
vuldb.com/?id.338598 (VDB-338598 | code-projects Student File Management System File Download download.php improper authorization)
vuldb.com/?ctiid.338598 (VDB-338598 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.725080 (Submit #725080 | Code-Projects 学生文件管理系统 V1.0 越权)
github.com/Bai-public/CVE/issues/5
code-projects.org/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.