CVE-2025-7124: code-projects Online Note Sharing Profile Image userprofile.php unrestricted upload
A vulnerability classified as critical has been found in code-projects Online Note Sharing 1.0. Affected is an unknown function of the file /dashboard/userprofile.php of the component Profile Image Handler. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7124?
CVE-2025-7124 is classified as a critical vulnerability.
How does CVE-2025-7124 affect my system?
CVE-2025-7124 allows for unrestricted file uploads through the profile image handler in the Online Note Sharing application.
How do I fix CVE-2025-7124?
To fix CVE-2025-7124, implement proper file upload validation and restrict allowed file types.
What versions of Online Note Sharing are affected by CVE-2025-7124?
CVE-2025-7124 affects all versions of Online Note Sharing 1.0.
What component of Online Note Sharing is vulnerable in CVE-2025-7124?
CVE-2025-7124 affects the Profile Image Handler component.