PT-2025-40886 · Unknown · Code-Projects Online Course Registration

Yanjun Li

·

Published

2025-10-06

·

Updated

2025-10-06

·

CVE-2025-11329

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Online Course Registration version 1.0
Description A flaw exists in code-projects Online Course Registration 1.0 that allows for SQL injection. The issue is located in the file /admin/manage-students.php and involves manipulation of the ID argument. This manipulation occurs within an unknown function. The attack can be initiated remotely and an exploit has been published.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-11329

Affected Products

Code-Projects Online Course Registration