SQL Injection Vulnerability in School Management System CMS by WeCodex
CVE-2018-25201
Key Information:
- Vendor
Wecodex Solutions
- Vendor
- CVE Published:
- 26 March 2026
Badges
What is CVE-2018-25201?
The School Management System CMS 1.0 is susceptible to an SQL injection vulnerability in its admin login interface. This flaw permits hackers to bypass authentication controls by injecting malicious SQL code through the username input. Using boolean-based blind SQL injection techniques, attackers can target the processlogin endpoint, enabling them to gain administrator access without the necessity of legitimate credentials. Organizations using this CMS should consider securing their systems against such exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
School Management System CMS 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
