PT-2025-37448 · Unknown · 1000Projects Online Project Report Submission/Evaluation System
Ustc-L1Nk
·
Published
2025-09-15
·
Updated
2025-09-18
·
CVE-2025-10425
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
1000projects Online Student Project Report Submission and Evaluation System version 1.0
Description
A vulnerability exists in 1000projects Online Student Project Report Submission and Evaluation System version 1.0 that allows for unrestricted file upload. The issue is related to the manipulation of the
new image argument within an unknown function of the /admin/controller/student controller.php file. This manipulation can be performed remotely. The exploit is publicly available.Recommendations
As a temporary workaround, restrict access to the
/admin/controller/student controller.php file to minimize the risk of exploitation.Exploit
Fix
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
1000Projects Online Project Report Submission/Evaluation System