Unrestricted File Upload Vulnerability in Code-Projects Computer Laboratory System
CVE-2025-14642
Key Information:
- Vendor
Code-projects
- Vendor
- CVE Published:
- 14 December 2025
Badges
What is CVE-2025-14642?
A significant vulnerability exists within the Code-Projects Computer Laboratory System, specifically affecting the 'technical_staff_pic.php' file. This flaw allows attackers to upload files without proper validation, posing serious security risks as unrestricted uploads enable remote exploitation. The manipulations of the 'image' argument can lead to arbitrary file uploads, which can be leveraged by threat actors for malicious purposes. This vulnerability has been publicly disclosed, increasing the urgency for organizations using this system to implement mitigations to avert possible exploitation.
Affected Version(s)
Computer Laboratory System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
