PT-2025-51139 · Unknown · Code-Projects Student Management System
Jjzr
·
Published
2025-12-14
·
Updated
2025-12-19
·
Jjzr
·
Published
2025-12-14
·
Updated
2025-12-19
·
9.8
Critical
| Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
stud no argument in the /admin/save student.php file can trigger this issue. The attack can be launched remotely. The exploit has been published./admin/save student.php file.
As a temporary workaround, restrict access to the /admin/save student.php file to minimize the risk of exploitation.
Sanitize the stud no input to prevent SQL injection attacks.Exploit
Fix
SQL injection
Special Elements Injection