PT-2025-43995 · Code Projects · Simple Food Ordering System

·

CVE-2025-12301

·

Published

2025-10-27

·

Updated

2025-11-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Simple Food Ordering System version 1.0
Description A security issue exists that allows for unrestricted file upload. This occurs due to manipulation of the photo argument within an unknown function of the /editproduct.php file. The attack can be initiated remotely, and the exploit has been publicly disclosed.
Recommendations Apply any available updates to address the unrestricted upload issue in the /editproduct.php file. As a temporary workaround, restrict access to the /editproduct.php file to minimize the risk of exploitation. Avoid uploading untrusted files through the photo parameter.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-12301

Affected Products

Simple Food Ordering System