Unrestricted File Upload Vulnerability in Itsourcecode Open Source Job Portal
CVE-2025-11078
Key Information:
- Vendor
Itsourcecode
- Status
- Vendor
- CVE Published:
- 27 September 2025
Badges
What is CVE-2025-11078?
A vulnerability exists in Itsourcecode Open Source Job Portal 1.0, specifically in the /admin/user/controller.php file, which enables unrestricted file uploads. The issue arises from the manipulation of the 'photo' argument, allowing attackers to upload malicious files remotely without proper authentication or validation. This creates security risks, as the exploit is publicly documented and can be easily executed, potentially leading to unauthorized access or other malicious actions within the application.
Affected Version(s)
Open Source Job Portal 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved