Unrestricted File Upload in Needyamin Library Card System 1.0 by Needyamin
CVE-2025-1355
Key Information:
- Vendor
- Needyamin
- Status
- Library Card System
- Vendor
- CVE Published:
- 16 February 2025
Badges
Summary
An unaddressed vulnerability has been identified in the Needyamin Library Card System 1.0, specifically within the /signup.php component related to the Add Picture functionality. This flaw allows malicious actors to exploit the system by performing unrestricted file uploads remotely. Such vulnerabilities can lead to significant security breaches, including unauthorized access to sensitive information and the potential for system compromise. Despite early notifications to the vendor regarding this security issue, there has been no acknowledgment or remediation, leaving users potentially at risk.
Affected Version(s)
Library Card System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved