Description
A vulnerability was found in code-projects Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file login_query.php. Performing manipulation of the argument stud_no results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.
Problem types
Product status
Timeline
| 2025-12-12: | Advisory disclosed |
| 2025-12-12: | VulDB entry created |
| 2025-12-12: | VulDB entry last update |
Credits
jjjjjzr (VulDB User)
References
vuldb.com/?id.336304 (VDB-336304 | code-projects Student File Management System login_query.php sql injection)
vuldb.com/?ctiid.336304 (VDB-336304 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.707101 (Submit #707101 | Code-projects Student File Management System 1.0 SQL Injection)
vuldb.com/?submit.709095 (Submit #709095 | Code-projects Student File Management System v1.0 Authentication Bypass by Primary Weakness (Duplicate))
github.com/jjjjj-zr/jjjjjzr2/issues/2
code-projects.org/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.