Description
A vulnerability was detected in Campcodes School File Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing manipulation of the argument stud_no results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.
Problem types
Product status
Timeline
| 2025-11-22: | Advisory disclosed |
| 2025-11-22: | VulDB entry created |
| 2025-11-23: | VulDB entry last update |
Credits
0x0A1lphj (VulDB User)
References
github.com/arpcyber070/CVE/issues/4
vuldb.com/?id.333322 (VDB-333322 | Campcodes School File Management System Login index.php sql injection)
vuldb.com/?ctiid.333322 (VDB-333322 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.696516 (Submit #696516 | Campcodes School File Management System V1.0 SQL Injection)
github.com/arpcyber070/CVE/issues/4
www.campcodes.com/