CVE-2025-6837: code-projects Library System profile.php unrestricted upload
A vulnerability classified as critical was found in code-projects Library System 1.0. Affected by this vulnerability is an unknown functionality of the file /profile.php. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6837?
CVE-2025-6837 is classified as a critical vulnerability due to its potential for remote exploitation.
How do I fix CVE-2025-6837?
To mitigate CVE-2025-6837, restrict file upload functionalities and validate input for the '/profile.php' script.
What systems are affected by CVE-2025-6837?
CVE-2025-6837 affects the Code-projects Library System version 1.0.
What type of attack is possible with CVE-2025-6837?
CVE-2025-6837 allows for unrestricted file uploads, which can lead to remote code execution.
Is CVE-2025-6837 easy to exploit?
Yes, CVE-2025-6837 is relatively easy to exploit due to its remote attack capability.