PT-2025-35182 · Unknown · Code-Projects Online Event Judging System

·

CVE-2025-9610

·

Published

2025-08-29

·

Updated

2025-11-13

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Online Event Judging System version 1.0
Description A vulnerability exists in the processing of the /create account.php file. Manipulation of the fname argument causes SQL injection, allowing for remote exploitation. The exploit has been publicly disclosed. Other parameters may also be affected.
Recommendations As a temporary workaround, consider restricting access to the /create account.php file until a fix is available. Sanitize the fname parameter to prevent SQL injection. Review and sanitize all other parameters used in the /create account.php file to identify and address potential vulnerabilities.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-9610

Affected Products

Code-Projects Online Event Judging System