CVE-2025-12256: code-projects Online Event Judging System edit_contestant.php sql injection
A weakness has been identified in code-projects Online Event Judging System 1.0. This vulnerability affects unknown code of the file /editcontestant.php. Executing manipulation of the argument contestantid can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12256?
CVE-2025-12256 is considered a high severity vulnerability due to its potential to allow remote SQL injection attacks.
How do I fix CVE-2025-12256?
To fix CVE-2025-12256, validate and sanitize the input for the contestant_id parameter in the /edit_contestant.php file.
What software is affected by CVE-2025-12256?
CVE-2025-12256 affects the Code-projects Online Event Judging System version 1.0.
How can CVE-2025-12256 be exploited?
CVE-2025-12256 can be exploited remotely by manipulating the contestant_id argument to execute SQL queries.
What are the implications of CVE-2025-12256 on data security?
Exploitation of CVE-2025-12256 could lead to unauthorized access to sensitive data within the database.