CVE-2025-14643: code-projects Simple Attendance Record System check.php sql injection
A vulnerability was found in code-projects Simple Attendance Record System 2.0. The affected element is an unknown function of the file /check.php. Performing manipulation of the argument student results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14643?
CVE-2025-14643 is considered a critical SQL injection vulnerability that can lead to unauthorized database access.
How do I fix CVE-2025-14643?
To fix CVE-2025-14643, you should sanitize and validate user inputs in the /check.php file to prevent SQL injection.
What kind of attack does CVE-2025-14643 enable?
CVE-2025-14643 enables remote SQL injection attacks that can compromise the integrity and security of the database.
Which software is affected by CVE-2025-14643?
CVE-2025-14643 specifically affects version 2.0 of the Code-projects Simple Attendance Record System.
Can CVE-2025-14643 be exploited remotely?
Yes, CVE-2025-14643 allows for remote exploitation through manipulation of the student argument in the /check.php file.