CVE-2025-11347

Severity CVSS v4.0:
MEDIUM
Type:
CWE-284 Improper Access Control
Publication date:
07/10/2025
Last modified:
14/10/2025

Description

A vulnerability was found in code-projects Student Crud Operation up to 3.3. This vulnerability affects the function move_uploaded_file of the file add.php of the component Add Student Page/Edit Student Page. Performing manipulation results in unrestricted upload. The attack can be initiated remotely. The exploit has been made public and could be used.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:code-projects:crud_operation_system:*:*:*:*:*:*:*:* 3.3 (including)