Description
A vulnerability was found in code-projects Library System 1.0. This impacts an unknown function of the file /return.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
Problem types
Product status
Timeline
| 2025-11-23: | Advisory disclosed |
| 2025-11-23: | VulDB entry created |
| 2025-11-23: | VulDB entry last update |
Credits
yudeshui (VulDB User)
References
vuldb.com/?id.333343 (VDB-333343 | code-projects Library System return.php sql injection)
vuldb.com/?ctiid.333343 (VDB-333343 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.699515 (Submit #699515 | code-projects Library System 1.0 SQL Injection)
github.com/rassec2/dbcve/issues/2
code-projects.org/