SQL Injection Vulnerability in Project Monitoring System by Code-Projects
CVE-2025-11074
Key Information:
- Vendor
Code-projects
- Vendor
- CVE Published:
- 27 September 2025
Badges
What is CVE-2025-11074?
A security flaw exists in the Project Monitoring System 1.0 developed by Code-Projects, where an unknown function in the /login.php file is vulnerable to SQL injection. This vulnerability allows attackers to manipulate the username/password arguments, potentially gaining unauthorized access to the database. The exploitation can occur remotely, making it critical for users to assess their installations and apply necessary patches to secure their systems. Detailed technical guidance, indicators of compromise, and potential mitigations can be found through various security advisories.
Affected Version(s)
Project Monitoring System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved