PT-2025-31489 · Code Projects · Exam Form Submission
Zhuchengqing
·
Published
2025-07-31
·
Updated
2025-07-31
·
CVE-2025-8372
Zhuchengqing
·
Published
2025-07-31
·
Updated
2025-07-31
·
CVE-2025-8372
7.5
High
Base vector | Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
code-projects Exam Form Submission version 1.0
Description:
A critical issue exists in code-projects Exam Form Submission 1.0. The vulnerability is due to a SQL injection flaw within an unknown functionality of the file `/admin/update s7.php`. Manipulation of the `credits` argument can lead to successful exploitation. The exploit for this issue has been publicly disclosed.
Recommendations:
As a temporary workaround, consider restricting access to the `/admin/update s7.php` file to minimize the risk of exploitation.
Avoid using the `credits` parameter in the affected file until the issue is resolved.
Exploit
Fix
Special Elements Injection
SQL injection