CVE-2025-13240: code-projects Student Information System searchquery.php sql injection
A vulnerability was detected in code-projects Student Information System 2.0. This affects an unknown part of the file /searchquery.php. Performing manipulation of the argument s results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13240?
CVE-2025-13240 has a high severity due to the potential for SQL injection attacks that can be exploited remotely.
How do I fix CVE-2025-13240?
To fix CVE-2025-13240, sanitize and validate all user inputs to protect against SQL injection attacks.
What products are affected by CVE-2025-13240?
CVE-2025-13240 affects the Code-projects Student Information System version 2.0.
Can CVE-2025-13240 be exploited remotely?
Yes, CVE-2025-13240 can be exploited remotely due to SQL injection vulnerabilities in the /searchquery.php file.
What type of vulnerability is CVE-2025-13240?
CVE-2025-13240 is classified as an SQL injection vulnerability.