CVE-2025-15196: code-projects Assessment Management login.php sql injection
A vulnerability was identified in code-projects Assessment Management 1.0. This affects an unknown part of the file login.php. Such manipulation of the argument userid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15196?
CVE-2025-15196 has been classified as a critical vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-15196?
To fix CVE-2025-15196, you should sanitize and validate user inputs in the login.php file to prevent SQL injection.
Who is affected by CVE-2025-15196?
CVE-2025-15196 affects users of the Code-projects Assessment Management version 1.0 software.
Can CVE-2025-15196 be exploited remotely?
Yes, CVE-2025-15196 can be exploited remotely, allowing attackers to execute SQL injection attacks.
Is there a known exploit available for CVE-2025-15196?
Yes, there are publicly available exploits for CVE-2025-15196 that demonstrate the SQL injection vulnerability.