CVE-2025-6883: code-projects Staff Audit System update_index.php sql injection
Published Jun 30, 2025
·Updated
A vulnerability classified as critical was found in code-projects Staff Audit System 1.0. This vulnerability affects unknown code of the file /updateindex.php. The manipulation of the argument updateid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Code-projects Staff Audit System
Carmelo Staff Audit System=1.0
Event History
Jun 30, 2025
CVE Published
via MITRE·02:32 AM
Data Sourced
via MITRE·02:32 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Jun 13, 58473
Event
via NVD·01:55 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-6883?
CVE-2025-6883 is classified as a critical vulnerability.
2
How does CVE-2025-6883 affect the Staff Audit System?
CVE-2025-6883 allows for SQL injection through the manipulation of the argument 'updateid' in the /update_index.php file.
3
Can CVE-2025-6883 be exploited remotely?
Yes, CVE-2025-6883 can be exploited remotely.
4
What version of the software is affected by CVE-2025-6883?
CVE-2025-6883 affects version 1.0 of the Code-projects Staff Audit System.
5
What should I do to mitigate CVE-2025-6883?
To mitigate CVE-2025-6883, update the affected software to the latest version that fixes the SQL injection vulnerability.