CVE-2025-0213

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 4, 2025
Updated: Jan 10, 2025
CWE ID 434
CWE ID 284

Summary

CVE-2025-0213 is a critical vulnerability affecting the Campcodes Project Management System 1.0. An attacker can exploit this issue by manipulating the argument file in the /forms/update_forms.php?action=change_pic2&id=4 endpoint. This results in an unrestricted upload, allowing the attacker to upload any content they wish. The exploit for this vulnerability has been made public, increasing the risk of attacks. Remotely initiated attacks are possible, making this a significant threat to systems running the vulnerable version of Campcodes Project Management System.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share