CVE-2025-7180: code-projects Staff Audit System login.php sql injection
Published Jul 8, 2025
·Updated
A vulnerability, which was classified as critical, has been found in code-projects Staff Audit System 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument User leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Code-projects Staff Audit System
Carmelo Staff Audit System=1.0
Event History
Jul 8, 2025
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 15, 58473
Event
via NVD·02:03 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-7180?
CVE-2025-7180 is classified as a critical vulnerability.
2
What type of vulnerability is CVE-2025-7180?
CVE-2025-7180 is a SQL injection vulnerability that affects the /login.php file.
3
How can CVE-2025-7180 be exploited?
CVE-2025-7180 can be exploited remotely by manipulating the User argument.
4
What software is affected by CVE-2025-7180?
CVE-2025-7180 affects the 'Staff Audit System' by code-projects.
5
How do I fix CVE-2025-7180?
To fix CVE-2025-7180, implement proper input validation and parameterized queries in the code.