code-projects Student Crud Operation Add Student Page/Edit Student add.php move_uploaded_file unrestricted upload
Vulnerability Description
A vulnerability was found in code-projects Student Crud Operation up to 3.3. This vulnerability affects the function move_uploaded_file of the file add.php of the component Add Student Page/Edit Student Page. Performing manipulation results in unrestricted upload. The attack can be initiated remotely. The exploit has been made public and could be used.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11347
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- px_kanten (VulDB User)
References
- https://vuldb.com/?id.327232
- https://vuldb.com/?ctiid.327232
- https://vuldb.com/?submit.664897
- https://github.com/romatdibrohiksnov/vulndb.com/tree/main/Student-Registration-Crud-Operation%20Unauthenticated%20Arbitrary%20File%20Upload%20leads%20to%20Remote%20Code%20Execution
- https://code-projects.org/
More from code-projects
View All →Affected Vendor
code-projects
View all reports →