Description
A vulnerability was found in code-projects Student Membership System 1.0. The affected element is an unknown function of the file /delete_user.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
Problem types
Product status
Timeline
| 2026-03-30: | VulDB entry created |
| 2026-03-31: | Advisory disclosed |
| 2026-03-31: | VulDB entry last update |
Credits
nomath (VulDB User)
References
vuldb.com/vuln/354295 (VDB-354295 | code-projects Student Membership System delete_user.php sql injection)
vuldb.com/vuln/354295/cti (VDB-354295 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/780402 (Submit #780402 | code-projects Student Membership System 1.0 SQL Injection)
github.com/maidangdang1/CVE/issues/3
code-projects.org/