CVE-2025-15205: code-projects Student File Management System download.php sql injection
A vulnerability was identified in code-projects Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /download.php. The manipulation of the argument istoreid leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15205?
CVE-2025-15205 has a high severity rating due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-15205?
To fix CVE-2025-15205, ensure proper parameter validation and use prepared statements to prevent SQL injection.
What type of attack can be executed using CVE-2025-15205?
CVE-2025-15205 allows for remote SQL injection attacks that can compromise the database.
Which software versions are affected by CVE-2025-15205?
CVE-2025-15205 specifically affects version 1.0 of the Code-projects Student File Management System.
What component is exploited in CVE-2025-15205?
The vulnerability in CVE-2025-15205 is exploited through an unknown functionality of the /download.php file.