Unrestricted Upload Vulnerability in Academico Profile Picture Handler
CVE-2025-10763
Key Information:
- Vendor
Academico-sis
- Status
- Vendor
- CVE Published:
- 21 September 2025
Badges
What is CVE-2025-10763?
An unrestricted upload vulnerability exists in the Profile Picture Handler of the Academico software, specifically in the /edit-photo functionality. This flaw allows attackers to upload arbitrary files remotely, potentially leading to malicious exploitations. This vulnerability has been publicly disclosed and poses significant security risks for users running affected versions. The vendor was notified about the vulnerability but has yet to respond, raising concerns about the responsiveness to security issues.
Affected Version(s)
academico d9a9e2636fbf7e5845ee086bcb03ca62faceb6ab
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved