A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/modules/lesson/index.php of the component List of Lessons Page. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-4404 A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/modules/lesson/index.php of the component List of Lessons Page. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 28 Feb 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Janobe
Janobe e-learning System
CPEs cpe:2.3:a:janobe:e-learning_system:1.0:*:*:*:*:*:*:*
Vendors & Products Janobe
Janobe e-learning System

Mon, 24 Feb 2025 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 23 Feb 2025 18:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/modules/lesson/index.php of the component List of Lessons Page. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely.
Title SourceCodester E-Learning System List of Lessons Page index.php unrestricted upload
Weaknesses CWE-284
CWE-434
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-02-24T12:09:13.587Z

Reserved: 2025-02-22T17:04:01.019Z

Link: CVE-2025-1590

cve-icon Vulnrichment

Updated: 2025-02-24T12:09:07.132Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-23T19:15:08.780

Modified: 2025-02-28T19:18:04.507

Link: CVE-2025-1590

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.