PT-2025-51131 · Code Projects · Student Management System
Jjjjjzr
·
Published
2025-12-13
·
Updated
2025-12-14
·
Jjjjjzr
·
Published
2025-12-13
·
Updated
2025-12-14
·
9.8
Critical
| Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
/admin/update student.php file. Manipulation of the stud id argument can lead to SQL injection. The issue is remotely exploitable and an exploit has been publicly released.Exploit
SQL injection
Special Elements Injection