CVE-2025-7190 Details
Description
A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. This affects an unknown part of the file /admin/student_edit_photo.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
A critical vulnerability allowing unrestricted file uploads has been identified in Code-Projects Library Management System version 2.0. The issue resides in the file '/admin/student_edit_photo.php', where the 'photo' argument can be manipulated to bypass file type and content validation. This vulnerability can be exploited remotely, and public knowledge of the exploit exists.
To address this vulnerability, it is recommended to implement proper file upload validation by whitelisting allowed file types, inspecting file contents, and storing uploaded files in non-executable directories. Additionally, web application firewall (WAF) rules can be applied to block uploads containing AntSword-specific payloads.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/y2xsec324/cve/issues/11 | CISA-ADP | ExploitIssue TrackingThird Party Advisory |
| https://code-projects.org/ | [email protected] | Product |
| https://github.com/y2xsec324/cve/issues/11 | [email protected] | ExploitIssue TrackingThird Party Advisory |
| https://vuldb.com/?ctiid.315129 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.315129 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.607202 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| fabian library management system | 2.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Oct 23, 2025 | CPE Deprecation Remap | [email protected] |
| Jul 11, 2025 | Initial Analysis | [email protected] |
| Jul 9, 2025 | CVE Modified | CISA-ADP |
| Jul 8, 2025 | New CVE Received | [email protected] |