Code-Projects Mobile Shop Management System File Upload Vulnerability

Vulnerability

A file upload vulnerability has been identified in Code-Projects Mobile Shop Management System version 1.0. The issue resides in the ExAddProduct.php file, where uploaded files are not properly validated. This flaw allows arbitrary files, including PHP scripts, to be uploaded and executed.

Impact

Exploitation of this vulnerability could lead to unauthorized file uploads, allowing attackers to upload and execute malicious PHP files on the server.

Reproduction

To reproduce this vulnerability, upload a file through the 'ProductImage' field in the ExAddProduct.php file. The uploaded file is not properly checked for its type or extension, allowing PHP files to be uploaded. Once uploaded, the file can be executed, potentially leading to a server compromise.

Added: Jan 27, 2026, 4:28 PM
Updated: Jan 27, 2026, 4:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
2.4
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.