CVE-2025-0346: code-projects Content Management System Publish News Page publishnews.php unrestricted upload
A vulnerability was found in code-projects Content Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/publishnews.php of the component Publish News Page. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0346?
CVE-2025-0346 has been classified as critical due to its unrestricted file upload vulnerability.
How does CVE-2025-0346 affect the system?
CVE-2025-0346 affects the Publish News Page component of the code-projects Content Management System, allowing for arbitrary file uploads.
How do I fix CVE-2025-0346?
To fix CVE-2025-0346, ensure proper validation and sanitization of the 'image' argument in the /admin/publishnews.php file.
Which versions of the code-projects Content Management System are affected by CVE-2025-0346?
CVE-2025-0346 affects version 1.0 of the code-projects Content Management System.
What type of vulnerability is CVE-2025-0346?
CVE-2025-0346 is categorized as an unrestricted file upload vulnerability.