PT-2026-91874 · Sourcecodester · Online Faculty Clearance System

·

CVE-2026-91005

·

Published

2026-09-15

·

Updated

2026-09-17

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SourceCodester Online Faculty Clearance System version 1.0
Description An unrestricted file upload issue exists in the Profile Picture Upload component within the production/edit picture.php file. A remote attacker can manipulate the File argument passed to the move uploaded file() function to upload arbitrary files to the server.
Recommendations Update SourceCodester Online Faculty Clearance System version 1.0 to a version that addresses this issue. As a temporary mitigation, restrict access to the production/edit picture.php file or disable the Profile Picture Upload functionality.

Exploit

Fix

Unrestricted File Upload

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91005

Affected Products

Online Faculty Clearance System