First published: Sun Feb 23 2025(Updated: )
A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/modules/lesson/index.php of the component List of Lessons Page. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
SourceCodester E-Learning System | ||
Janobe Elearning System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1590 has been classified as critical due to the potential for unrestricted file uploads.
To fix CVE-2025-1590, you should secure the file upload functionality by implementing file type restrictions and validating user inputs.
CVE-2025-1590 affects the List of Lessons Page functionality in the SourceCodester E-Learning System.
Exploiting CVE-2025-1590 can lead to unauthorized file uploads and potentially allow attackers to execute malicious code.
CVE-2025-1590 impacts SourceCodester E-Learning System version 1.0.