Code-Projects Online Lot Reservation System Unrestricted File Upload Vulnerability

Vulnerability

A vulnerability allowing unrestricted file uploads has been identified in Code-Projects Online Lot Reservation System version 1.0. The issue resides in the activity.php file, where the directory parameter is manipulated to bypass file type restrictions, leading to arbitrary file uploads and path traversal. This vulnerability can be exploited remotely, with the potential for uploaded files to be executed on the server.

Impact

Exploitation of this vulnerability allows for arbitrary file uploads, which can include malicious scripts that are executed on the server, potentially leading to full server control.

Reproduction

To reproduce this vulnerability, first log in as an administrator. Then, upload a file through the activity.php page by manipulating the directory parameter to traverse to the web root. After the file is uploaded, it can be accessed and executed as a script.

Added: Apr 27, 2026, 3:23 PM
Updated: Apr 27, 2026, 3:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.6
remediation
0.0
relevance
6.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.