CVE-2025-14537: code-projects Class and Exam Timetable Management preview7.php sql injection
A weakness has been identified in code-projects Class and Exam Timetable Management 1.0. Affected by this issue is some unknown functionality of the file /preview7.php. This manipulation of the argument courseyearsection/semester causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14537?
CVE-2025-14537 is classified as a high-severity vulnerability due to the potential for SQL injection.
How can I fix CVE-2025-14537?
To fix CVE-2025-14537, ensure that all user inputs to the /preview7.php file are properly sanitized and validated.
What type of vulnerability is CVE-2025-14537?
CVE-2025-14537 is an SQL injection vulnerability that allows attackers to manipulate database queries.
In which software is CVE-2025-14537 found?
CVE-2025-14537 is found in version 1.0 of the code-projects Class and Exam Timetable Management software.
Can CVE-2025-14537 be exploited remotely?
Yes, CVE-2025-14537 can be exploited remotely, highlighting the need for immediate remediation.