Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file production/edit_picture.php of the component Profile Picture Upload. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used. | |
| Title | SourceCodester Online Faculty Clearance System Profile Picture Upload edit_picture.php move_uploaded_file unrestricted upload | |
| First Time appeared |
Sourcecodester
Sourcecodester online Faculty Clearance System |
|
| Weaknesses | CWE-284 CWE-434 |
|
| CPEs | cpe:2.3:a:sourcecodester:online_faculty_clearance_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sourcecodester
Sourcecodester online Faculty Clearance System |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-15T06:15:12.465Z
Reserved: 2026-09-14T15:51:00.921Z
Link: CVE-2026-91005
No data.
Status : Received
Published: 2026-09-15T07:16:33.830
Modified: 2026-09-15T07:16:33.830
Link: CVE-2026-91005
No data.
OpenCVE Enrichment
No data.