CVE-2025-10616: itsourcecode E-Commerce Website users.php unrestricted upload
A security flaw has been discovered in itsourcecode E-Commerce Website 1.0. Affected is an unknown function of the file /admin/users.php. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has been released to the public and may be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10616?
CVE-2025-10616 has a high severity due to the potential for unrestricted file uploads that could lead to remote exploitation.
How do I fix CVE-2025-10616?
To fix CVE-2025-10616, restrict file upload permissions and implement validation checks for file types in the /admin/users.php function.
What systems are affected by CVE-2025-10616?
CVE-2025-10616 affects version 1.0 of the itsourcecode E-Commerce Website.
Can CVE-2025-10616 be exploited remotely?
Yes, CVE-2025-10616 can be exploited remotely due to the nature of the vulnerability in the system.
What are the potential impacts of CVE-2025-10616?
The potential impacts of CVE-2025-10616 include unauthorized code execution and significant data breach risks.