Unrestricted File Upload Vulnerability in Campcodes Project Management System
CVE-2025-0213
Key Information:
- Vendor
- Campcodes
- Vendor
- CVE Published:
- 4 January 2025
Badges
Summary
A vulnerability exists in the Campcodes Project Management System 1.0 that allows unauthorized users to upload files unrestrictedly via the update_forms.php endpoint. This flaw can lead to remote code execution as it manipulates the 'file' argument without proper validation, enabling attackers to execute arbitrary files on the server. The vulnerability can be exploited from a distance, posing significant risks to system integrity and confidentiality. Immediate steps should be taken to secure the affected areas of the application.
Affected Version(s)
Project Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved