PT-2025-31778 · Code Projects · Kitchen Treasure

Haoatao

·

Published

2025-08-03

·

Updated

2025-08-08

·

CVE-2025-8504

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Kitchen Treasure version 1.0
Description A critical vulnerability exists in code-projects Kitchen Treasure. The issue affects an unknown part of the file /userregistration.php. Manipulation of the photo argument leads to unrestricted upload, and the attack can be initiated remotely. The exploit has been disclosed to the public.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-8504

Affected Products

Kitchen Treasure