Description
A weakness has been identified in Campcodes School File Management System 1.0. This impacts an unknown function of the file /update_query.php. This manipulation of the argument stud_id causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.
Problem types
Product status
Timeline
| 2025-12-07: | Advisory disclosed |
| 2025-12-07: | VulDB entry created |
| 2025-12-07: | VulDB entry last update |
Credits
davidluiswang (VulDB User)
References
vuldb.com/?id.334652 (VDB-334652 | Campcodes School File Management System update_query.php sql injection)
vuldb.com/?ctiid.334652 (VDB-334652 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.700896 (Submit #700896 | Campcodes School File Management System 1.0 SQL Injection)
github.com/IdealDreamLast/PublicCVE/issues/1
www.campcodes.com/