Aller au contenu

Fiche vulnérabilité

CVE-2025-13574 : faille élevée fabian online bidding system (CVSS 7.2)

Description

A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd of the file /administrator/addcategory.php. This manipulation of the argument catimage causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

En bref

Sévérité
Élevée (CVSS 7.2)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
24 nov. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • fabian online bidding system

Références

Rechercher une autre vulnérabilité dans la base CVE