CVE-2025-3855

A vulnerability was found in CodeCanyon RISE Ultimate Project Manager 3.8.2 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php/team_members/save_profile_image/ of the component Profile Picture Handler. The manipulation of the argument profile_image_file leads to improper control of resource identifiers. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Configurations

No configuration.

History

23 Apr 2025, 14:08

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en CodeCanyon RISE Ultimate Project Manager 3.8.2 y se clasificó como problemática. Este problema afecta a una funcionalidad desconocida del archivo /index.php/team_members/save_profile_image/ del componente Profile Picture Handler. La manipulación del argumento profile_image_file conlleva un control inadecuado de los identificadores de recursos. El ataque puede ejecutarse remotamente. Se ha hecho público el exploit y puede que sea utilizado.

22 Apr 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-22 01:15

Updated : 2025-04-23 14:08


NVD link : CVE-2025-3855

Mitre link : CVE-2025-3855

CVE.ORG link : CVE-2025-3855


JSON object : View

Products Affected

No product.

CWE
CWE-99

Improper Control of Resource Identifiers ('Resource Injection')