This page lists publicly disclosed CVE vulnerabilities affecting carmelo computer_laboratory_system (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-14642 | A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the file technical_staff_pic.php. Such manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | [email protected] | 2.0 | 0.04% | 2025-12-14 | 2026-04-29 |
| CVE-2025-14641 | A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the file admin/admin_pic.php. This manipulation of the argument image causes unrestricted upload. The attack may be initiated remotely. The exploit has been published and may be used. | [email protected] | 2.0 | 0.04% | 2025-12-14 | 2026-04-29 |
| CVE-2025-60307 | code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on the login page can bypass login attempts. | [email protected] | 9.8 | 0.05% | 2025-10-10 | 2025-10-21 |
| CVE-2025-56295 | code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by uploading PHP backdoor files when modifying personal avatar information and use web shell connection tools to obtain server permissions. | [email protected] | 7.3 | 0.03% | 2025-09-16 | 2025-09-18 |