CVE-2025-1593
SourceCodester Best Employee Management System Profile Picture unrestricted upload
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability classified as critical has been found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file /_hr_soft/assets/uploadImage/Profile/ of the component Profile Picture Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely.
Es wurde eine Schwachstelle in SourceCodester Best Employee Management System 1.0 entdeckt. Sie wurde als kritisch eingestuft. Es geht dabei um eine nicht klar definierte Funktion der Datei /_hr_soft/assets/uploadImage/Profile/ der Komponente Profile Picture Handler. Mittels Manipulieren mit unbekannten Daten kann eine unrestricted upload-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk passieren.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2025-02-22 CVE Reserved
- 2025-02-23 CVE Published
- 2025-02-24 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.296577 | Vdb Entry | |
https://vuldb.com/?submit.505212 | Third Party Advisory | |
https://www.sourcecodester.com | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
SourceCodester Search vendor "SourceCodester" | Best Employee Management System Search vendor "SourceCodester" for product "Best Employee Management System" | 1.0 Search vendor "SourceCodester" for product "Best Employee Management System" and version "1.0" | en |
Affected
|