CVE-2025-11426: projectworlds Advanced Library Management System edit_book.php unrestricted upload
A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /editbook.php. The manipulation of the argument image results in unrestricted upload. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11426?
CVE-2025-11426 has a high severity rating due to its potential for unrestricted file uploads.
How do I fix CVE-2025-11426?
To fix CVE-2025-11426, implement proper file validation and restrict the types of files that can be uploaded in the Advanced Library Management System.
What does CVE-2025-11426 affect?
CVE-2025-11426 affects the 'edit_book.php' file in the Advanced Library Management System by allowing unrestricted uploads through the 'image' argument.
Who is affected by CVE-2025-11426?
Users of the Advanced Library Management System version 1.0 are affected by CVE-2025-11426.
Is CVE-2025-11426 a known vulnerability?
Yes, CVE-2025-11426 is a known vulnerability that has been publicly documented and classified.