CVE-2025-56295EPSS p24.3%

CVE-2025-56295CVE-2025-56295

carmelo / computer_laboratory_system

Description

code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by uploading PHP backdoor files when modifying personal avatar information and use web shell connection tools to obtain server permissions.

Scoring

CVSS 7.3 ()
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
EPSS0.32% probability of exploitation · percentile 24.3% · 2026-08-18T12:04:07Z
Last modified2026-07-05
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.