First published: Thu Jan 09 2025(Updated: )
A vulnerability was found in code-projects Content Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/publishnews.php of the component Publish News Page. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
code-projects Content Management System | ||
code-projects Content Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0346 has been classified as critical due to its unrestricted file upload vulnerability.
CVE-2025-0346 affects the Publish News Page component of the code-projects Content Management System, allowing for arbitrary file uploads.
To fix CVE-2025-0346, ensure proper validation and sanitization of the 'image' argument in the /admin/publishnews.php file.
CVE-2025-0346 affects version 1.0 of the code-projects Content Management System.
CVE-2025-0346 is categorized as an unrestricted file upload vulnerability.