Code-Projects College Management System Unrestricted File Upload Vulnerability

Vulnerability

A critical vulnerability allowing unrestricted file uploads has been identified in Code-Projects College Management System version 1.0. This issue resides in the Admin/student.php file, where the profile_image argument can be manipulated to upload malicious files. The vulnerability can be exploited remotely, and public knowledge of the exploit exists.

Impact

Exploitation of this vulnerability allows for arbitrary file uploads, which could be used to upload malicious files such as web shells that execute code on the server.

Reproduction

To reproduce this vulnerability, send a POST request to the Admin/student.php endpoint with the profile_image field set to a file containing PHP code, such as a web shell. The uploaded file will be saved to the images directory, where it can be accessed and executed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
7.5
exploitability
9.5
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.