CVE-2025-13289: 1000projects Design & Development of Student Database Management System SubjectDetails.php sql injection
A vulnerability was detected in 1000projects Design & Development of Student Database Management System 1.0. Affected is an unknown function of the file /TeacherLogin/Academics/SubjectDetails.php. The manipulation of the argument SubCode results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13289?
CVE-2025-13289 is categorized as a critical vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2025-13289?
To mitigate CVE-2025-13289, sanitize and validate all user inputs in the SubjectDetails.php file, especially the SubCode argument.
What systems are affected by CVE-2025-13289?
CVE-2025-13289 affects version 1.0 of the 1000projects Design & Development of Student Database Management System.
Can CVE-2025-13289 be exploited remotely?
Yes, CVE-2025-13289 can be exploited remotely if an attacker can access the vulnerable SubjectDetails.php file.
What are the implications of CVE-2025-13289?
Exploitation of CVE-2025-13289 can lead to unauthorized access to the database, allowing attackers to manipulate or retrieve sensitive data.