CVE-2025-56295 - CERT CVE
ID CVE-2025-56295
Sažetak code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by uploading PHP backdoor files when modifying personal avatar information and use web shell connection tools to obtain server permissions.
Reference
CVSS
Base: 7.3
Impact: 5.2
Exploitability:2.1
Pristup
VektorSloženostAutentikacija
NETWORK LOW LOW
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH NONE
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Zadnje važnije ažuriranje 16-09-2025 - 19:15
Objavljeno 16-09-2025 - 15:15