Description
A vulnerability was determined in code-projects Student File Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/login_query.php. Executing manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Problem types
Product status
Timeline
| 2025-12-12: | Advisory disclosed |
| 2025-12-12: | VulDB entry created |
| 2025-12-12: | VulDB entry last update |
Credits
jjjjjzr (VulDB User)
References
vuldb.com/?id.336305 (VDB-336305 | code-projects Student File Management System login_query.php sql injection)
vuldb.com/?ctiid.336305 (VDB-336305 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.707109 (Submit #707109 | Code-projects Student File Management System 1.0 SQL Injection)
vuldb.com/?submit.709074 (Submit #709074 | Code-projects Student File Management System v1.0 Authentication Bypass by Primary Weakness (Duplicate))
github.com/jjjjj-zr/jjjjjzr3/issues/1
code-projects.org/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.