Description
A vulnerability was determined in code-projects Student Result Manager 1.0. This affects an unknown function of the file src/students/Database.java. This manipulation of the argument roll/name/gpa causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
In code-projects Student Result Manager 1.0 wurde eine Schwachstelle gefunden. Dies betrifft einen unbekannten Teil der Datei src/students/Database.java. Die Veränderung des Parameters roll/name/gpa resultiert in sql injection. Der Angriff kann über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.
Problem types
Product status
Timeline
2025-10-09: | Advisory disclosed |
2025-10-09: | VulDB entry created |
2025-10-09: | VulDB entry last update |
Credits
lakshay12311 (VulDB User)
References
vuldb.com/?id.327710 (VDB-327710 | code-projects Student Result Manager Database.java sql injection)
vuldb.com/?ctiid.327710 (VDB-327710 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.670256 (Submit #670256 | code-projects Student Result Manager 1.0 SQL Injection)
github.com/...-Discovery/blob/main/Student Result Manager.md
code-projects.org/