CVE-2025-13573: projectworlds can pass malicious payloads add_book.php unrestricted upload
A security flaw has been discovered in projectworlds can pass malicious payloads up to 1.0. This vulnerability affects unknown code of the file /addbook.php. The manipulation of the argument image results in unrestricted upload. The attack can be executed remotely. The exploit has been released to the public and may be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13573?
CVE-2025-13573 has a high severity due to its potential for remote code execution via unrestricted file uploads.
How do I fix CVE-2025-13573?
To fix CVE-2025-13573, you should sanitize file upload inputs and implement validation checks on uploaded files in the /add_book.php file.
What does CVE-2025-13573 affect?
CVE-2025-13573 affects versions of Projectworlds projectworlds up to and including 1.0.
Can CVE-2025-13573 be exploited remotely?
Yes, CVE-2025-13573 can be exploited remotely, allowing an attacker to upload malicious files.
What type of attack does CVE-2025-13573 enable?
CVE-2025-13573 enables an unrestricted file upload attack, potentially leading to remote code execution.