THREAT OPS › Threat News › [NVD] CVE-2025-70151 (HIGH 8.8) — code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-accessible uploads/ directory using the origina
[NVD] CVE-2025-70151 (HIGH 8.8) — code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-accessible uploads/ directory using the origina
CVE-2025-70151 CVSS: 8.8 HIGH Published: 2026-02-18T18:24:20.757
code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-accessible uploads/ directory using the original, user-supplied filename without validating the file
Indicators of compromise
- CVE-2025-70151cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-70151