CVE-2025-7412: code-projects Library System profile.php unrestricted upload
A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user/student/profile.php. The manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7412?
CVE-2025-7412 is rated as critical due to its potential for unrestricted file upload vulnerabilities.
How do I fix CVE-2025-7412?
To fix CVE-2025-7412, ensure proper validation and sanitization of the 'image' argument in the /user/student/profile.php file.
What software is affected by CVE-2025-7412?
CVE-2025-7412 affects Code-projects Library System version 1.0.
What type of attack can be executed using CVE-2025-7412?
CVE-2025-7412 allows attackers to perform unrestricted file uploads, leading to potential exploitation of the system.
Where is the vulnerability located in CVE-2025-7412?
The vulnerability CVE-2025-7412 is located in the /user/student/profile.php file of the Code-projects Library System.