Vendorscarmelocomputer_laboratory_systemall versions
Vulnerabilities

carmelo (Carmelo Garcia) Computer Laboratory System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2025-60307
code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on the login page can bypass login attempts.
Published 2025-10-10 · Modified
9.8EPSS 0.004
CVE-2025-56295
code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by uploading PHP backdoor files when modifying personal avatar information and use web shell connection tools to obtain server permissions.
Published 2025-09-16 · Modified
7.3EPSS 0.003
CVE-2025-14641
code-projects Computer Laboratory System admin_pic.php unrestricted upload
Published 2025-12-14 · Analyzed
7.2EPSS 0.004
CVE-2025-14642
code-projects Computer Laboratory System technical_staff_pic.php unrestricted upload
Published 2025-12-14 · Analyzed
7.2EPSS 0.004