CVE-2025-3969: codeprojects News Publishing Site Dashboard Edit Category Page edit-category.php unrestricted upload
A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processing of the file /edit-category.php of the component Edit Category Page. The manipulation of the argument categoryimage leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3969?
CVE-2025-3969 is rated as critical due to its potential impact on the security of the News Publishing Site Dashboard.
How do I fix CVE-2025-3969?
To fix CVE-2025-3969, you should update the CodeProjects News Publishing Site Dashboard to the latest version that includes a patch for this vulnerability.
What component is affected by CVE-2025-3969?
The affected component in CVE-2025-3969 is the Edit Category Page, specifically the processing of the file /edit-category.php.
What type of vulnerability is CVE-2025-3969?
CVE-2025-3969 involves improper handling of the category_image argument which can lead to unauthorized manipulation.
Who is affected by CVE-2025-3969?
All users of CodeProjects News Publishing Site Dashboard version 1.0 are potentially affected by CVE-2025-3969.