SQL Injection Vulnerability in Student File Management System by Code-Projects
CVE-2025-14646
Key Information:
- Vendor
Code-projects
- Vendor
- CVE Published:
- 14 December 2025
Badges
What is CVE-2025-14646?
A security flaw has been identified in the Student File Management System version 1.0, specifically in the /admin/delete_student.php file. The vulnerability arises from improper validation of the stud_id parameter, allowing attackers to execute SQL injection attacks. This can enable unauthorized access to sensitive data and may be exploited from a remote location. Immediate attention is required to mitigate this risk and secure the application.
Affected Version(s)
Student File Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
