CVE 6.9 MEDIUM

ProjectsAndPrograms School Management System editNotes.php unrestricted upload_CVE-2025-11656

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A weakness has been identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This affects an unknown function of the file /assets/editNotes.php. Executing manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.

Basic Information

ID CVE-2025-11656
Source VulDB
Published Oct 13, 2025 at 02:02

Affected Product

Vendor ProjectsAndPrograms
Product School Management System
Version 6b6fae5426044f89c08d0dd101c7fa71f9042a59
Affected Versions ProjectsAndPrograms School Management System 6b6fae5426044f89c08d0dd101c7fa71f9042a59

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.