CVE-2025-13241: code-projects Student Information System index.php sql injection
Published Nov 16, 2025
·Updated
A flaw has been found in code-projects Student Information System 2.0. This vulnerability affects unknown code of the file /index.php. Executing manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
Affected Software
2 affected components
Code-projects Student Information System
Fabian Student Information System=2.0
Event History
Nov 16, 2025
CVE Published
via MITRE·07:02 AM
Data Sourced
via MITRE·07:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-13241?
CVE-2025-13241 has a high severity rating due to its potential to allow SQL injection attacks.
2
How do I fix CVE-2025-13241?
To fix CVE-2025-13241, ensure proper input validation and use prepared statements to prevent SQL injection.
3
Which software is affected by CVE-2025-13241?
CVE-2025-13241 affects version 2.0 of the code-projects Student Information System.
4
Can CVE-2025-13241 be exploited remotely?
Yes, CVE-2025-13241 can be exploited remotely through manipulated input in the Username argument.
5
What kind of vulnerability is CVE-2025-13241?
CVE-2025-13241 is categorized as an SQL injection vulnerability.