CVE-2025-8174: code-projects Voting System candidates_add.php unrestricted upload
Published Jul 26, 2025
·Updated
A vulnerability was found in code-projects Voting System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/candidatesadd.php. The manipulation of the argument photo leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Code-projects Voting System
Fabian Voting System=1.0
Event History
Jul 26, 2025
CVE Published
via MITRE·01:04 AM
Data Sourced
via MITRE·01:04 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Jun 16, 58473
Event
via NVD·01:42 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-8174?
CVE-2025-8174 is classified as a critical vulnerability.
2
How do I fix CVE-2025-8174?
To fix CVE-2025-8174, implement restrictions on file uploads in the /admin/candidates_add.php functionality.
3
What does CVE-2025-8174 affect?
CVE-2025-8174 affects the code-projects Voting System 1.0.
4
What type of vulnerability is CVE-2025-8174?
CVE-2025-8174 is an unrestricted file upload vulnerability.
5
How can CVE-2025-8174 be exploited?
CVE-2025-8174 can be exploited remotely by manipulating the photo argument in the upload functionality.