A weakness has been identified in code-projects Online...
Moderate severity
Unreviewed
Published
Nov 24, 2025
to the GitHub Advisory Database
•
Updated Dec 2, 2025
Description
Published by the National Vulnerability Database
Nov 24, 2025
Published to the GitHub Advisory Database
Nov 24, 2025
Last updated
Dec 2, 2025
A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd of the file /administrator/addcategory.php. This manipulation of the argument catimage causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.
References