Unrestricted File Upload Vulnerability in Online Note Sharing by Code Projects
CVE-2025-7124
Key Information:
- Vendor
Code-projects
- Status
- Vendor
- CVE Published:
- 7 July 2025
Badges
What is CVE-2025-7124?
A vulnerability has been identified in the Online Note Sharing application, specifically within the Profile Image Handler component of the userprofile.php file. This flaw allows unauthorized users to manipulate the 'image' argument, leading to unrestricted file uploads. As a result, attackers could potentially upload malicious files remotely, posing serious security risks. Since this exploit has been publicly disclosed, it is crucial for users to review their security measures and incorporate necessary patches to safeguard their systems.
Affected Version(s)
Online Note Sharing 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved