---
id: CVE-2025-11656
title: >-
  A weakness has been identified in ProjectsAndPrograms School Management System
  up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59
summary: >-
  A weakness has been identified in ProjectsAndPrograms School Management System
  up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This affects an unknown
  function of the file /assets/editNotes.php. Executing manipulation of the
  argument Fil…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-284
  - CWE-434
  - CWE-434
vendor: oranbyte
product: school_management_system
affected:
  - school_management_system = 1.0
published: '2025-10-13'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11656'
references:
  - url: 'https://github.com/qqy-123/cve/issues/1'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.328073'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.328073'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.665603'
    label: cna@vuldb.com
  - url: 'https://github.com/qqy-123/cve/issues/1'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00594
epssPercentile: 0.46678
ingestedAt: '2026-10-08T12:39:48.699Z'
---

## Overview

A weakness has been identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This affects an unknown function of the file /assets/editNotes.php. Executing manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.

## Affected

- `school_management_system = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
