CVE-2025-14642: code-projects Computer Laboratory System technical_staff_pic.php unrestricted upload
A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the file technicalstaffpic.php. Such manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14642?
CVE-2025-14642 is considered a high severity vulnerability due to the potential for unrestricted file uploads.
How do I fix CVE-2025-14642?
To fix CVE-2025-14642, validate and restrict the types of files that can be uploaded in the technical_staff_pic.php file.
What type of attack can be executed through CVE-2025-14642?
CVE-2025-14642 allows attackers to conduct remote file upload attacks that can lead to arbitrary code execution.
Which software is affected by CVE-2025-14642?
CVE-2025-14642 affects version 1.0 of the Code-projects Computer Laboratory System.
Can CVE-2025-14642 be exploited remotely?
Yes, CVE-2025-14642 can be exploited remotely due to the unrestricted nature of the file upload.