Code Projects · Scholars Tracking System · CVE-2025-14951
**Name of the Vulnerable Software and Affected Versions**
code-projects Scholars Tracking System version 1.0
**Description**
A security issue exists in code-projects Scholars Tracking System 1.0. Manipulation of the `post content` argument within a file, `/home.php`, can lead to SQL injection. This issue is remotely exploitable and has been publicly disclosed. The vulnerable element is an unknown function within the `/home.php` file.
**Recommendations**
Apply any available updates to address the SQL injection issue in the `/home.php` file.
As a temporary workaround, consider restricting or sanitizing the `post content` argument to prevent SQL injection attacks.