code-projects Student File Management System 1.0 File Download /download.php store_id विशेषाधिकार वाढीचे प्रमाण वाढले

एक असुरक्षितता जी समस्याग्रस्त म्हणून वर्गीकृत आहे, ती code-projects Student File Management System 1.0 मध्ये आढळली आहे. प्रभावित आहे अज्ञात फंक्शन फाइल /download.php च्या घटक File Download Handler च्या. सॉफ्टवेअरमध्ये store_id या आर्ग्युमेंटमध्ये वापर विशेषाधिकार वाढीचे प्रमाण वाढले घडवून आणतो. CWE वापरून समस्या घोषित केल्याने CWE-285 कडे नेले जाते. कमजोरी प्रकाशित करण्यात आली होती 28/12/2025. सल्ला डाउनलोडसाठी github.com येथे शेअर केला आहे. ही कमतरता CVE-2025-15213 या नावाने ओळखली जाते. हल्ला दूरस्थपणे सुरू करणे शक्य आहे. तांत्रिक तपशील उपलब्ध आहेत. यासाठी एक एक्स्प्लॉइट उपलब्ध आहे. शोषण सार्वजनिकपणे उघड झाले आहे आणि वापरले जाऊ शकते. सध्याच्या घडीला अंदाजे USD $0-$5k असू शकतो. MITRE ATT&CK प्रकल्पाने हल्ल्याची तंत्रज्ञान T1548.002 म्हणून घोषित केली आहे. हे प्रूफ-ऑफ-कॉन्सेप्ट म्हणून घोषित केले आहे. github.com या ठिकाणी शोषण डाउनलोडसाठी शेअर केले आहे. 0-डे म्हणून अंदाजे अंडरग्राउंड किंमत सुमारे $0-$5k होती. VulDB is the best source for vulnerability data and more expert information about this specific topic.

7 बदल · 97 डेटा पॉइंट्स

शेतअद्ययावत 2/6
30/12/2025 04:36 AM
अद्ययावत 3/6
31/12/2025 03:18 PM
अद्ययावत 4/6
01/01/2026 08:13 PM
अद्ययावत 5/6
02/01/2026 03:57 PM
अद्ययावत 6/6
03/01/2026 02:46 PM
software_vendorcode-projectscode-projectscode-projectscode-projectscode-projects
software_nameStudent File Management SystemStudent File Management SystemStudent File Management SystemStudent File Management SystemStudent File Management System
software_version1.01.01.01.01.0
software_componentFile Download HandlerFile Download HandlerFile Download HandlerFile Download HandlerFile Download Handler
software_file/download.php/download.php/download.php/download.php/download.php
software_argumentstore_idstore_idstore_idstore_idstore_id
vulnerability_cweCWE-285 (विशेषाधिकार वाढीचे प्रमाण वाढले)CWE-285 (विशेषाधिकार वाढीचे प्रमाण वाढले)CWE-285 (विशेषाधिकार वाढीचे प्रमाण वाढले)CWE-285 (विशेषाधिकार वाढीचे प्रमाण वाढले)CWE-285 (विशेषाधिकार वाढीचे प्रमाण वाढले)
vulnerability_risk11111
cvss3_vuldb_avNNNNN
cvss3_vuldb_acLLLLL
cvss3_vuldb_prLLLLL
cvss3_vuldb_uiNNNNN
cvss3_vuldb_sUUUUU
cvss3_vuldb_cLLLLL
cvss3_vuldb_iNNNNN
cvss3_vuldb_aNNNNN
cvss3_vuldb_ePPPPP
cvss3_vuldb_rcRRRRR
advisory_urlhttps://github.com/Bai-public/CVE/issues/5https://github.com/Bai-public/CVE/issues/5https://github.com/Bai-public/CVE/issues/5https://github.com/Bai-public/CVE/issues/5https://github.com/Bai-public/CVE/issues/5
exploit_availability11111
exploit_publicity11111
exploit_urlhttps://github.com/Bai-public/CVE/issues/5https://github.com/Bai-public/CVE/issues/5https://github.com/Bai-public/CVE/issues/5https://github.com/Bai-public/CVE/issues/5https://github.com/Bai-public/CVE/issues/5
source_cveCVE-2025-15213CVE-2025-15213CVE-2025-15213CVE-2025-15213CVE-2025-15213
cna_responsibleVulDBVulDBVulDBVulDBVulDB
software_typeProject Management SoftwareProject Management SoftwareProject Management SoftwareProject Management SoftwareProject Management Software
cvss2_vuldb_avNNNNN
cvss2_vuldb_acLLLLL
cvss2_vuldb_ciPPPPP
cvss2_vuldb_iiNNNNN
cvss2_vuldb_aiNNNNN
cvss2_vuldb_ePOCPOCPOCPOCPOC
cvss2_vuldb_rcURURURURUR
cvss4_vuldb_avNNNNN
cvss4_vuldb_acLLLLL
cvss4_vuldb_prLLLLL
cvss4_vuldb_uiNNNNN
cvss4_vuldb_vcLLLLL
cvss4_vuldb_viNNNNN
cvss4_vuldb_vaNNNNN
cvss4_vuldb_ePPPPP
cvss2_vuldb_auSSSSS
cvss2_vuldb_rlNDNDNDNDND
cvss3_vuldb_rlXXXXX
cvss4_vuldb_atNNNNN
cvss4_vuldb_scNNNNN
cvss4_vuldb_siNNNNN
cvss4_vuldb_saNNNNN
cvss2_vuldb_basescore4.04.04.04.04.0
cvss2_vuldb_tempscore3.43.43.43.43.4
cvss3_vuldb_basescore4.34.34.34.34.3
cvss3_vuldb_tempscore3.93.93.93.93.9
cvss3_meta_basescore4.34.34.34.34.3
cvss3_meta_tempscore4.14.14.14.14.1
cvss4_vuldb_bscore5.35.35.35.35.3
cvss4_vuldb_btscore2.12.12.12.12.1
advisory_date1766876400 (28/12/2025)1766876400 (28/12/2025)1766876400 (28/12/2025)1766876400 (28/12/2025)1766876400 (28/12/2025)
price_0day$0-$5k$0-$5k$0-$5k$0-$5k$0-$5k
cve_nvd_summaryA vulnerability has been found in code-projects Student File Management System 1.0. The affected element is an unknown function of the file /download.php of the component File Download Handler. The manipulation of the argument store_id leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.A vulnerability has been found in code-projects Student File Management System 1.0. The affected element is an unknown function of the file /download.php of the component File Download Handler. The manipulation of the argument store_id leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.A vulnerability has been found in code-projects Student File Management System 1.0. The affected element is an unknown function of the file /download.php of the component File Download Handler. The manipulation of the argument store_id leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.A vulnerability has been found in code-projects Student File Management System 1.0. The affected element is an unknown function of the file /download.php of the component File Download Handler. The manipulation of the argument store_id leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.A vulnerability has been found in code-projects Student File Management System 1.0. The affected element is an unknown function of the file /download.php of the component File Download Handler. The manipulation of the argument store_id leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
cvss4_cna_avNNNNN
cvss4_cna_acLLLLL
cvss4_cna_atNNNNN
cvss4_cna_prLLLLL
cvss4_cna_uiNNNNN
cvss4_cna_vcLLLLL
cvss4_cna_viNNNNN
cvss4_cna_vaNNNNN
cvss4_cna_scNNNNN
cvss4_cna_siNNNNN
cvss4_cna_saNNNNN
cvss4_cna_bscore5.35.35.35.35.3
cvss3_cna_avNNNNN
cvss3_cna_acLLLLL
cvss3_cna_prLLLLL
cvss3_cna_uiNNNNN
cvss3_cna_sUUUUU
cvss3_cna_cLLLLL
cvss3_cna_iNNNNN
cvss3_cna_aNNNNN
cvss3_cna_basescore4.34.34.34.34.3
cvss2_cna_avNNNNN
cvss2_cna_acLLLLL
cvss2_cna_auSSSSS
cvss2_cna_ciPPPPP
cvss2_cna_iiNNNNN
cvss2_cna_aiNNNNN
cvss2_cna_basescore44444
euvd_idEUVD-2025-205679EUVD-2025-205679EUVD-2025-205679EUVD-2025-205679EUVD-2025-205679
cnnvd_idCNNVD-202512-5487CNNVD-202512-5487CNNVD-202512-5487CNNVD-202512-5487
cnnvd_nameCode-Projects Student File Management System 授权问题漏洞Code-Projects Student File Management System 授权问题漏洞Code-Projects Student File Management System 授权问题漏洞Code-Projects Student File Management System 授权问题漏洞
cnnvd_hazardlevel3333
cnnvd_create2025-12-312025-12-312025-12-312025-12-31
cnnvd_publish2025-12-302025-12-302025-12-302025-12-30
cnnvd_update2025-12-312026-01-012026-01-022026-01-03

Do you know our Splunk app?

Download it now for free!