Vulnerabilities (CVE)

Filtered by vendor Carmelo Subscribe
Filtered by product Computer Laboratory System
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-14642 1 Carmelo 1 Computer Laboratory System 2025-12-16 5.8 MEDIUM 4.7 MEDIUM
A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the file technical_staff_pic.php. Such manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-14641 1 Carmelo 1 Computer Laboratory System 2025-12-16 5.8 MEDIUM 4.7 MEDIUM
A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the file admin/admin_pic.php. This manipulation of the argument image causes unrestricted upload. The attack may be initiated remotely. The exploit has been published and may be used.
CVE-2025-60307 1 Carmelo 1 Computer Laboratory System 2025-10-21 N/A 9.8 CRITICAL
code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on the login page can bypass login attempts.
CVE-2025-56295 1 Carmelo 1 Computer Laboratory System 2025-09-18 N/A 7.3 HIGH
code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by uploading PHP backdoor files when modifying personal avatar information and use web shell connection tools to obtain server permissions.