CVE-2025-7477: code-projects Simple Car Rental System add_cars.php unrestricted upload
A vulnerability, which was classified as critical, has been found in code-projects Simple Car Rental System 1.0. This issue affects some unknown processing of the file /admin/addcars.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7477?
CVE-2025-7477 is classified as a critical vulnerability.
What is affected by CVE-2025-7477?
CVE-2025-7477 affects the Simple Car Rental System version 1.0, specifically the file /admin/add_cars.php.
How do I fix CVE-2025-7477?
To fix CVE-2025-7477, implement proper validation and restrictions on file uploads within the affected system.
What type of attack can be executed using CVE-2025-7477?
An attacker can exploit CVE-2025-7477 to perform unrestricted file uploads, potentially leading to further exploitation.
What is the impact of exploiting CVE-2025-7477?
Exploiting CVE-2025-7477 can lead to unauthorized access and control over the server, resulting in data breaches or system compromise.