Code-Projects Content Management System and News-Buzz Unrestricted File Upload Vulnerability

Vulnerability

A vulnerability allowing arbitrary file upload has been identified in Code-Projects Content Management System and News-Buzz version 1.0. This issue arises in the file /admin/editposts.php, where the image argument can be manipulated to bypass file type restrictions. The vulnerability can be exploited remotely, allowing attackers to upload malicious scripts that could be executed on the server, potentially leading to unauthorized control, data theft, or further attacks on system security.

Impact

Exploitation of this vulnerability allows for unrestricted file uploads, which can be used to upload and execute malicious scripts on the server. This could result in unauthorized server control, data theft, or additional attacks that compromise system security.

Reproduction

To reproduce this vulnerability, send a POST request to /NEWS-BUZZ/admin/editposts.php with the image argument manipulated to include a file named '111.php'. Change the Content-Type to 'image/gif' to bypass file type detection. Once the file is uploaded, it can be accessed through the 'allpostpics' directory and executed as a web shell.

Added: Dec 29, 2025, 5:23 PM
Updated: Dec 29, 2025, 5:23 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
10.0
exploitability
9.7
remediation
0.0
relevance
1.6
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.