Unrestricted File Upload in SourceCodester Best Employee Management System
CVE-2025-1593
5.1MEDIUM
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 23 February 2025
What is CVE-2025-1593?
The SourceCodester Best Employee Management System version 1.0 contains a vulnerability in the Profile Picture Handler component. This flaw allows for unrestricted file uploads through the file path /_hr_soft/assets/uploadImage/Profile/. Attackers can exploit this vulnerability remotely, potentially leading to unauthorized access and execution of arbitrary code.
Affected Version(s)
Best Employee Management System 1.0