PT-2025-51130 · Code Projects · Student Management System
Jjjjjzr
·
Published
2025-12-13
·
Updated
2025-12-14
·
Jjjjjzr
·
Published
2025-12-13
·
Updated
2025-12-14
·
9.8
Critical
| Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
firstname argument can lead to SQL injection. The attack can be carried out remotely. The exploit has been publicly released.firstname argument to prevent SQL injection attacks.
As a temporary workaround, restrict access to the '/admin/save user.php' file.Exploit
Fix
SQL injection
Special Elements Injection