PT-2025-35644 · Code Projects · Mobile Shop Management System

111Ctx

·

Published

2025-09-02

·

Updated

2025-09-03

·

CVE-2025-9841

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Mobile Shop Management System version 1.0
Description A security issue has been identified in code-projects Mobile Shop Management System version 1.0. The vulnerability involves unrestricted upload capabilities due to the manipulation of the ProductImage argument within the file AddNewProduct.php. This issue is exploitable remotely. The exploit has been publicly disclosed.
Recommendations As a temporary workaround, consider restricting file uploads through the AddNewProduct.php file until a fix is available.

Exploit

Fix

Unrestricted File Upload

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-9841

Affected Products

Mobile Shop Management System