CVE-2025-6884: code-projects Staff Audit System search_index.php sql injection
Published Jun 30, 2025
·Updated
A vulnerability, which was classified as critical, has been found in code-projects Staff Audit System 1.0. This issue affects some unknown processing of the file /searchindex.php. The manipulation of the argument Search leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Code-projects Staff Audit System
Carmelo Staff Audit System=1.0
Event History
Jun 30, 2025
CVE Published
via MITRE·03:02 AM
Data Sourced
via MITRE·03:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Jun 13, 58473
Event
via NVD·07:01 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-6884?
CVE-2025-6884 is classified as a critical vulnerability.
2
How do I fix CVE-2025-6884?
To fix CVE-2025-6884, ensure that all input in the /search_index.php file is properly sanitized to prevent SQL injection.
3
What type of attack does CVE-2025-6884 facilitate?
CVE-2025-6884 facilitates SQL injection attacks through the manipulation of the Search argument.
4
Can CVE-2025-6884 be exploited remotely?
Yes, CVE-2025-6884 can be exploited remotely by attackers.
5
What software is affected by CVE-2025-6884?
CVE-2025-6884 affects version 1.0 of the code-projects Staff Audit System.