PT-2025-3832 · Unknown · Code-Projects Online Bike Rental System

Huandtx

·

Published

2025-01-09

·

Updated

2025-01-09

·

CVE-2025-0335

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Online Bike Rental System version 1.0
Description A critical issue has been found in the Change Image Handler component, allowing for unrestricted upload. This can be exploited remotely. The issue affects some unknown functionality of the component. Other endpoints might also be affected.
Recommendations For code-projects Online Bike Rental System version 1.0, consider disabling the Change Image Handler component until a patch is available to prevent unrestricted upload. Restrict access to potentially vulnerable endpoints to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-0335

Affected Products

Code-Projects Online Bike Rental System