CVE-2025-10102: code-projects Online Event Judging System index.php sql injection
A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown function of the file /index.php. Performing manipulation of the argument Username results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10102?
CVE-2025-10102 has a high severity due to its potential for SQL injection vulnerabilities.
How do I fix CVE-2025-10102?
To fix CVE-2025-10102, sanitize and validate all user inputs, particularly the Username argument in /index.php.
Can CVE-2025-10102 be exploited remotely?
Yes, CVE-2025-10102 can be exploited remotely without requiring local access.
What type of vulnerability is CVE-2025-10102?
CVE-2025-10102 is classified as an SQL injection vulnerability affecting the Online Event Judging System.
Which software is affected by CVE-2025-10102?
CVE-2025-10102 affects version 1.0 of the code-projects Online Event Judging System.