CVE-2025-12862: projectworlds Online Notes Sharing Platform userprofile.php unrestricted upload
A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php. Such manipulation of the argument image leads to unrestricted upload. The attack may be performed from remote. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12862?
CVE-2025-12862 has a moderate severity level due to the risk of unrestricted file uploads.
How do I fix CVE-2025-12862?
To fix CVE-2025-12862, implement proper validation and sanitization for uploaded files in userprofile.php.
What systems are affected by CVE-2025-12862?
CVE-2025-12862 affects Projectworlds Online Notes Sharing Platform 1.0.
What type of vulnerability is CVE-2025-12862?
CVE-2025-12862 is a file upload vulnerability that allows for unrestricted file upload.
Can CVE-2025-12862 be exploited remotely?
Yes, CVE-2025-12862 can be exploited remotely through manipulation of the image argument.