CVE-2025-10425

A vulnerability was identified in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The impacted element is an unknown function of the file /admin/controller/student_controller.php. Such manipulation of the argument new_image leads to unrestricted upload. The attack may be performed from remote. The exploit is publicly available and might be used.
References
Link Resource
https://github.com/lan041221/cvec/issues/23 Exploit Third Party Advisory Issue Tracking
https://vuldb.com/?ctiid.323859 Permissions Required VDB Entry
https://vuldb.com/?id.323859 Third Party Advisory VDB Entry
https://vuldb.com/?submit.647175 Third Party Advisory VDB Entry
https://vuldb.com/?submit.647177 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:1000projects:online_student_project_report_submission_and_evaluation_system:1.0:*:*:*:*:*:*:*

History

18 Sep 2025, 19:09

Type Values Removed Values Added
CPE cpe:2.3:a:1000projects:online_student_project_report_submission_and_evaluation_system:1.0:*:*:*:*:*:*:*
First Time 1000projects
1000projects online Student Project Report Submission And Evaluation System
References () https://github.com/lan041221/cvec/issues/23 - () https://github.com/lan041221/cvec/issues/23 - Exploit, Third Party Advisory, Issue Tracking
References () https://vuldb.com/?ctiid.323859 - () https://vuldb.com/?ctiid.323859 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.323859 - () https://vuldb.com/?id.323859 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.647175 - () https://vuldb.com/?submit.647175 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.647177 - () https://vuldb.com/?submit.647177 - Third Party Advisory, VDB Entry

15 Sep 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-15 04:15

Updated : 2025-09-18 19:09


NVD link : CVE-2025-10425

Mitre link : CVE-2025-10425

CVE.ORG link : CVE-2025-10425


JSON object : View

Products Affected

1000projects

  • online_student_project_report_submission_and_evaluation_system
CWE
CWE-284

Improper Access Control

CWE-434

Unrestricted Upload of File with Dangerous Type