CVE-2026-91005 | SourceCodester Online Faculty Clearance System 1.0 Profile Picture Upload edit_picture.php move_uploaded_file File unrestricted upload

SecurityVulns

A vulnerability identified as critical has been detected in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file production/edit_picture.php of the component Profile Picture Upload. Performing a manipulation of the argument File results in unrestricted upload.

This vulnerability is reported as CVE-2026-91005. The attack is possible to be carried out remotely. Moreover, an exploit is present.VulDB Recent EntriesRead More