PT-2025-43914 · Code Projects · Code-Projects Online Event Judging System

Seeu1

·

Published

2025-10-27

·

Updated

2025-10-27

·

CVE-2025-12255

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Online Event Judging System version 1.0
Description A security flaw exists in code-projects Online Event Judging System 1.0. Manipulation of the fullname argument in the /add contestant.php file can lead to SQL injection. Remote exploitation is possible, and an exploit has been publicly released.
Recommendations Apply input validation and sanitization to the fullname parameter in the /add contestant.php file.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-12255

Affected Products

Code-Projects Online Event Judging System