SQL Injection Vulnerability in 1000projects Student Database Management System
CVE-2025-13289
Key Information:
- Vendor
1000projects
- Vendor
- CVE Published:
- 17 November 2025
Badges
What is CVE-2025-13289?
A vulnerability has been identified in the Student Database Management System developed by 1000projects, specifically in the function located in /TeacherLogin/Academics/SubjectDetails.php. This security flaw allows an attacker to manipulate the 'SubCode' argument, leading to a potential SQL injection attack. Remote attackers can exploit this vulnerability to insert malicious SQL queries, compromising the integrity and confidentiality of the database. Given that the exploit has been made public, it is crucial for users of this system to apply necessary patches and monitor for unusual activities.
Affected Version(s)
Design & Development of Student Database Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
