Description
A vulnerability was found in code-projects Coaching Management System 1.0. This affects an unknown function of the file /cims/modules/admin/reply.php of the component POST Handler. Performing a manipulation of the argument complaintreply results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Problem types
Product status
Timeline
| 2026-04-27: | Advisory disclosed |
| 2026-04-27: | VulDB entry created |
| 2026-04-27: | VulDB entry last update |
Credits
imad alvi (VulDB User)
References
vuldb.com/vuln/359830 (VDB-359830 | code-projects Coaching Management System POST reply.php sql injection)
vuldb.com/vuln/359830/cti (VDB-359830 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/802414 (Submit #802414 | code-projects Coaching Management System in PHP unknown (latest version as of April 2026) SQL Injection)
github.com/...QL-Injection-in-Coaching-Management-System.git
code-projects.org/