CVE-2025-7413: code-projects Library System profile.php unrestricted upload
A vulnerability classified as critical has been found in code-projects Library System 1.0. This affects an unknown part of the file /user/teacher/profile.php. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7413?
CVE-2025-7413 is classified as a critical vulnerability.
How do I fix CVE-2025-7413?
To fix CVE-2025-7413, restrict file upload capabilities in the library system to prevent unauthorized image uploads.
What type of attack can CVE-2025-7413 facilitate?
CVE-2025-7413 can facilitate a remote code execution attack due to unrestricted file uploads.
Which part of the software is affected by CVE-2025-7413?
CVE-2025-7413 affects the file /user/teacher/profile.php in the code-projects Library System.
Who is impacted by CVE-2025-7413?
Users of code-projects Library System version 1.0 are impacted by CVE-2025-7413.