Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12449 | A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processing of the file /edit-category.php of the component Edit Category Page. The manipulation of the argument category_image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
Wed, 30 Apr 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Code-projects
Code-projects news Publishing Site Dashboard |
|
| CPEs | cpe:2.3:a:code-projects:news_publishing_site_dashboard:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Code-projects
Code-projects news Publishing Site Dashboard |
Mon, 28 Apr 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 27 Apr 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processing of the file /edit-category.php of the component Edit Category Page. The manipulation of the argument category_image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Title | codeprojects News Publishing Site Dashboard Edit Category Page edit-category.php unrestricted upload | |
| Weaknesses | CWE-284 CWE-434 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-04-28T22:00:29.031Z
Reserved: 2025-04-26T07:11:05.416Z
Link: CVE-2025-3969
Updated: 2025-04-28T14:46:28.618Z
Status : Analyzed
Published: 2025-04-27T12:15:14.077
Modified: 2025-04-30T18:38:01.393
Link: CVE-2025-3969
No data.
OpenCVE Enrichment
No data.
EUVD