CVE-2025-13574: code-projects Online Bidding System addcategory.php categoryadd unrestricted upload
A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd of the file /administrator/addcategory.php. This manipulation of the argument catimage causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13574?
CVE-2025-13574 is considered a high severity vulnerability due to its potential for unrestricted file uploads.
How do I fix CVE-2025-13574?
To fix CVE-2025-13574, you should implement strict validation on the 'catimage' upload argument to restrict file types and sizes.
What systems are affected by CVE-2025-13574?
CVE-2025-13574 affects Code-projects Online Bidding System version 1.0.
What type of attack is possible with CVE-2025-13574?
An attacker can exploit CVE-2025-13574 to perform remote code execution through unrestricted file uploads.
Is there a patch available for CVE-2025-13574?
Currently, there is no known patch publicly available for CVE-2025-13574; it is recommended to apply mitigations manually.