CVE-2025-7175: code-projects E-Commerce Site users_photo.php unrestricted upload
A vulnerability was found in code-projects E-Commerce Site 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/usersphoto.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7175?
CVE-2025-7175 has been classified as critical due to the potential for unrestricted file uploads.
How do I fix CVE-2025-7175?
To fix CVE-2025-7175, implement proper validation and restrictions on file uploads in the /admin/users_photo.php file.
What software is affected by CVE-2025-7175?
CVE-2025-7175 affects the Code-projects E-Commerce Site version 1.0.
Can CVE-2025-7175 be exploited remotely?
Yes, CVE-2025-7175 can be exploited remotely due to its unrestricted upload feature.
What impact does CVE-2025-7175 have on security?
The impact of CVE-2025-7175 is significant as it allows attackers to upload malicious files, potentially leading to further system compromise.