CVE-2026-7134: code-projects Online Lot Reservation System edithousepic.php unrestricted upload
A vulnerability was identified in code-projects Online Lot Reservation System 1.0. Affected is an unknown function of the file /edithousepic.php. Such manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7134?
The severity of CVE-2026-7134 is considered high due to its potential for unrestricted file uploads.
How do I fix CVE-2026-7134?
To fix CVE-2026-7134, implement proper validation and sanitization of the 'image' parameter in edithousepic.php.
What are the potential impacts of CVE-2026-7134?
CVE-2026-7134 can lead to remote code execution, data breach, and compromise of the server.
Is my system vulnerable if I use Code-Projects Online Lot Reservation System version 1.0?
Yes, if you are using Code-Projects Online Lot Reservation System version 1.0, your system is vulnerable to CVE-2026-7134.
How can I mitigate risks associated with CVE-2026-7134?
Mitigate risks by restricting file upload types and implementing access controls on the Upload functionality.