CVE-2025-15404: campcodes School File Management System save_file.php unrestricted upload
A security vulnerability has been detected in campcodes School File Management System 1.0. The affected element is an unknown function of the file /save_file.php. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15404?
The severity of CVE-2025-15404 is currently rated as critical due to the potential for remote exploitation and unrestricted file uploads.
How do I fix CVE-2025-15404?
To fix CVE-2025-15404, ensure that proper validations and restrictions are applied to file uploads in the /save_file.php function.
What attack vector is associated with CVE-2025-15404?
CVE-2025-15404 can be exploited remotely by manipulating the File argument during file upload.
Which version of Campcodes software is affected by CVE-2025-15404?
CVE-2025-15404 affects version 1.0 of the Campcodes School File Management System.
What are the potential impacts of exploiting CVE-2025-15404?
Exploiting CVE-2025-15404 could allow attackers to upload arbitrary files, potentially leading to code execution or system compromise.