CVE-2025-7755: code-projects Online Ordering System edit_product.php unrestricted upload
A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/editproduct.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7755?
CVE-2025-7755 is rated as critical due to unrestricted file uploads that can be exploited.
How do I fix CVE-2025-7755?
To fix CVE-2025-7755, ensure proper validation and restrictions on file uploads in the /admin/edit_product.php component.
What is the impact of CVE-2025-7755?
The impact of CVE-2025-7755 includes allowing remote attackers to upload malicious files via the image argument.
Which systems are affected by CVE-2025-7755?
CVE-2025-7755 affects version 1.0 of the Code-projects Online Ordering System.
What does unrestricted upload mean in CVE-2025-7755?
Unrestricted upload in CVE-2025-7755 means that attackers can upload any type of file, including potentially harmful ones.