CVE-2026-1423: code-projects Online Examination System admin_pic.php unrestricted upload
A vulnerability was determined in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /adminpic.php. Executing a manipulation can lead to unrestricted upload. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1423?
CVE-2026-1423 has been classified as a high-severity vulnerability due to its potential for malicious file uploads.
How do I fix CVE-2026-1423?
To fix CVE-2026-1423, implement proper validation and restrictions on file uploads in the /admin_pic.php script.
What are the implications of CVE-2026-1423?
CVE-2026-1423 allows attackers to upload arbitrary files, potentially compromising the server's integrity and exposing sensitive data.
Which versions of the Online Examination System are affected by CVE-2026-1423?
CVE-2026-1423 affects version 1.0 of the code-projects Online Examination System.
Can CVE-2026-1423 lead to remote code execution?
Yes, CVE-2026-1423 could enable remote code execution if an attacker successfully uploads a malicious script.