Junglewise Threat Intelligence

CVE-2025-56295: code-projects Computer Laboratory System unrestricted file upload in avatar settings

CVE-2025-56295 · Severity: high · CVSS 7.3 · Published 2025-09-16

Vendors: Code-Projects.

Executive brief

The Computer Laboratory System, a management platform for academic labs, contains a security flaw in its user profile settings. An authorized staff member can upload a malicious script instead of a standard profile picture, allowing them to take control of the underlying server. This could lead to the theft of sensitive data, unauthorized access to laboratory records, or a complete shutdown of the management system.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in code-projects Computer Laboratory System 1.0 within the 'Change Picture' functionality. The application fails to properly validate the file extension or content of uploaded profile images, allowing an authenticated user with 'Staff' privileges to upload PHP backdoor files. By accessing the uploaded file via a direct URL, an attacker can establish a web shell connection (e.g., using AntSword) to execute arbitrary commands on the server. This remote attack requires low privileges but currently assumes some level of user interaction or specific path predictability for execution.

Affected products

  • code-projects Computer Laboratory System 1.0

Timeline

  • 2025-09-16: disclosed
  • 2025-09-16: advisory

References

Related threats