CVE-2025-11656

A weakness has been identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This affects an unknown function of the file /assets/editNotes.php. Executing manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
References
Link Resource
https://github.com/qqy-123/cve/issues/1 Exploit Third Party Advisory Issue Tracking
https://vuldb.com/?ctiid.328073 Permissions Required VDB Entry
https://vuldb.com/?id.328073 Third Party Advisory VDB Entry
https://vuldb.com/?submit.665603 Third Party Advisory VDB Entry
https://github.com/qqy-123/cve/issues/1 Exploit Third Party Advisory Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:oranbyte:school_management_system:1.0:*:*:*:*:*:*:*

History

16 Oct 2025, 18:26

Type Values Removed Values Added
First Time Oranbyte
Oranbyte school Management System
CPE cpe:2.3:a:oranbyte:school_management_system:1.0:*:*:*:*:*:*:*
References () https://github.com/qqy-123/cve/issues/1 - () https://github.com/qqy-123/cve/issues/1 - Exploit, Third Party Advisory, Issue Tracking
References () https://vuldb.com/?ctiid.328073 - () https://vuldb.com/?ctiid.328073 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.328073 - () https://vuldb.com/?id.328073 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.665603 - () https://vuldb.com/?submit.665603 - Third Party Advisory, VDB Entry

14 Oct 2025, 14:15

Type Values Removed Values Added
References () https://github.com/qqy-123/cve/issues/1 - () https://github.com/qqy-123/cve/issues/1 -

13 Oct 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-13 03:15

Updated : 2025-10-16 18:26


NVD link : CVE-2025-11656

Mitre link : CVE-2025-11656

CVE.ORG link : CVE-2025-11656


JSON object : View

Products Affected

oranbyte

  • school_management_system
CWE
CWE-284

Improper Access Control

CWE-434

Unrestricted Upload of File with Dangerous Type