CVE-2025-7755: Unrestricted Upload in code-projects Online Ordering System
A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/edit_product.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-7755: Unrestricted Upload in code-projects Online Ordering System
Description
A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/edit_product.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulDB
- Date Reserved
- 2025-07-17T10:36:11.313Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 68796115a83201eaace9b977
Added to database: 7/17/2025, 8:46:13 PM
Last updated: 7/17/2025, 8:46:13 PM
Views: 1
Related Threats
CVE-2025-50240: n/a
HighCVE-2025-23269: CWE-1423: Exposure of Sensitive Information caused by Shared Microarchitectural Predictor State that Influences Transient Execution in NVIDIA Jetson Orin and Xavier Devices
MediumCVE-2025-7754: SQL Injection in code-projects Patient Record Management System
MediumCVE-2025-23270: CWE-392: Missing Report of Error Condition in NVIDIA Jetson Orin, IGX Orin and Xavier Devices
HighCVE-2025-7753: SQL Injection in code-projects Online Appointment Booking System
MediumActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.