CVE-2025-6294: code-projects Hostel Management System contact.php sql injection
A vulnerability was found in code-projects Hostel Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /contact.php. The manipulation of the argument hostelname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6294?
CVE-2025-6294 has been classified as critical due to its potential for SQL injection vulnerabilities.
How do I fix CVE-2025-6294?
To fix CVE-2025-6294, sanitize and validate all user input, especially the hostel_name parameter in the /contact.php file.
Can CVE-2025-6294 be exploited remotely?
Yes, CVE-2025-6294 can be exploited remotely, making it a significant threat to affected systems.
Which software is affected by CVE-2025-6294?
CVE-2025-6294 affects the code-projects Hostel Management System version 1.0.
What type of vulnerability is CVE-2025-6294?
CVE-2025-6294 is a SQL injection vulnerability found in the /contact.php file, specifically in the hostel_name argument.