CVE-2025-2392: code-projects Online Class and Exam Scheduling System activate.php sql injection
A vulnerability, which was classified as critical, has been found in code-projects Online Class and Exam Scheduling System 1.0. This issue affects some unknown processing of the file /pages/activate.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2392?
CVE-2025-2392 is classified as critical due to its potential for SQL injection vulnerabilities.
How do I fix CVE-2025-2392?
To fix CVE-2025-2392, implement proper input validation and parameterized queries in the /pages/activate.php file.
What software is affected by CVE-2025-2392?
CVE-2025-2392 affects Code-projects Online Class and Exam Scheduling System version 1.0.
What type of attack can exploit CVE-2025-2392?
CVE-2025-2392 can be exploited through SQL injection attacks targeting the id parameter.
Is there a patch available for CVE-2025-2392?
Currently, there is no specific patch available for CVE-2025-2392; users should apply manual code changes as a workaround.