CVE-2025-13574
code-projects Online Bidding System addcategory.php categoryadd unrestricted upload
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 5.1EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
24 nov 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd of the file /administrator/addcategory.php. This manipulation of the argument catimage causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Produtos afetados
code-projects · Online Bidding SystemQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →