PT-2025-31489 · Code Projects · Exam Form Submission

Zhuchengqing

·

Published

2025-07-31

·

Updated

2025-07-31

·

CVE-2025-8372

CVSS v2.0
7.5
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P

Name of the Vulnerable Software and Affected Versions:

code-projects Exam Form Submission version 1.0

Description:

A critical issue exists in code-projects Exam Form Submission 1.0. The vulnerability is due to a SQL injection flaw within an unknown functionality of the file `/admin/update s7.php`. Manipulation of the `credits` argument can lead to successful exploitation. The exploit for this issue has been publicly disclosed.

Recommendations:

As a temporary workaround, consider restricting access to the `/admin/update s7.php` file to minimize the risk of exploitation.

Avoid using the `credits` parameter in the affected file until the issue is resolved.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-8372

Affected Products

Exam Form Submission