CVE-2025-15197

MEDIUM

Anirbandutta News-buzz - Improper Access Control

Title source: rule

Description

A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vulnerability affects unknown code of the file /admin/editposts.php. Performing manipulation of the argument image results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.

Scores

CVSS v3 4.7
EPSS 0.0005
EPSS Percentile 16.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-284 CWE-434
Status published

Affected Products (2)

anirbandutta/news-buzz
code-projects/content_management_system

Timeline

Published Dec 29, 2025
Tracked Since Feb 18, 2026