PT-2025-37448 · Unknown · 1000Projects Online Project Report Submission/Evaluation System

Ustc-L1Nk

·

Published

2025-09-15

·

Updated

2025-09-18

·

CVE-2025-10425

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 1000projects Online Student Project Report Submission and Evaluation System version 1.0
Description A vulnerability exists in 1000projects Online Student Project Report Submission and Evaluation System version 1.0 that allows for unrestricted file upload. The issue is related to the manipulation of the new image argument within an unknown function of the /admin/controller/student controller.php file. This manipulation can be performed remotely. The exploit is publicly available.
Recommendations As a temporary workaround, restrict access to the /admin/controller/student controller.php file to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-10425

Affected Products

1000Projects Online Project Report Submission/Evaluation System