A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php. Such manipulation of the argument image leads to unrestricted upload. The attack may be performed from remote. The exploit is publicly available and might be used.
📦
online_notes_sharing_platform
Vendor: projectworlds
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
1
Remote Access
Total CVEs
6
Total Indexed
Avg. EPSS
0.39%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
2.1
CVSS
CVE-2025-12862
RCE
Severity: LOW
5.5
CVSS
A vulnerability has been found in projectworlds Online Notes Sharing Platform 1.0. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument User leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: MEDIUM