CVE-2025-14940: code-projects Scholars Tracking System delete_user.php sql injection
A vulnerability was determined in code-projects Scholars Tracking System 1.0. The affected element is an unknown function of the file /admin/deleteuser.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14940?
CVE-2025-14940 has a medium severity rating due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-14940?
To fix CVE-2025-14940, sanitize and validate input parameters in the /admin/delete_user.php file to prevent SQL injection.
Who is affected by CVE-2025-14940?
CVE-2025-14940 affects users of Code-projects Scholars Tracking System 1.0.
What type of vulnerability is CVE-2025-14940?
CVE-2025-14940 is an SQL injection vulnerability that can be exploited remotely.
Can CVE-2025-14940 be exploited remotely?
Yes, CVE-2025-14940 can be exploited remotely, allowing attackers to manipulate database queries.