CVE-2025-1593: SourceCodester Best Employee Management System Profile Picture unrestricted upload
A vulnerability classified as critical has been found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file /hrsoft/assets/uploadImage/Profile/ of the component Profile Picture Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1593?
CVE-2025-1593 is classified as a critical vulnerability.
How can I mitigate CVE-2025-1593?
To mitigate CVE-2025-1593, implement strict validation on file uploads to restrict allowed file types and sizes.
What component is affected by CVE-2025-1593?
CVE-2025-1593 affects the Profile Picture Handler component of the SourceCodester Best Employee Management System.
What risk does CVE-2025-1593 pose?
CVE-2025-1593 poses a risk of unrestricted file upload, potentially allowing attackers to upload malicious files.
Is there a patch available for CVE-2025-1593?
As of now, there is no information available regarding a patch for CVE-2025-1593.