CVE-2025-14642
- EPSS 0.05%
- Veröffentlicht 14.12.2025 02:32:06
- Zuletzt bearbeitet 16.12.2025 20:07:09
A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the file technical_staff_pic.php. Such manipulation of the argument image leads to unrestricted upload. The attack may be launched remo...
CVE-2025-14641
- EPSS 0.05%
- Veröffentlicht 14.12.2025 02:02:07
- Zuletzt bearbeitet 16.12.2025 20:06:40
A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the file admin/admin_pic.php. This manipulation of the argument image causes unrestricted upload. The attack may be initiated remotel...
CVE-2025-60307
- EPSS 0.06%
- Veröffentlicht 10.10.2025 00:00:00
- Zuletzt bearbeitet 21.10.2025 17:41:41
code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on the login page can bypass login attempts.
CVE-2025-56295
- EPSS 0.02%
- Veröffentlicht 16.09.2025 00:00:00
- Zuletzt bearbeitet 18.09.2025 16:50:45
code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by uploading PHP backdoor files when modifying personal avatar information and use web shell connection tools to obtain server permissions.