CVE-2025-8271: code-projects Exam Form Submission delete_s3.php sql injection
Published Jul 28, 2025
·Updated
A vulnerability was found in code-projects Exam Form Submission 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/deletes3.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Code-projects Exam Form Submission
Code-projects Exam Form Submission=1.0
Event History
Jul 28, 2025
CVE Published
via MITRE·10:02 AM
Data Sourced
via MITRE·10:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Jun 23, 58473
Event
via NVD·11:32 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-8271?
CVE-2025-8271 is classified as a critical severity vulnerability.
2
How does CVE-2025-8271 work?
CVE-2025-8271 exploits an SQL injection vulnerability through manipulation of the ID argument in the file /admin/delete_s3.php.
3
Who is affected by CVE-2025-8271?
CVE-2025-8271 affects users of Code-projects Exam Form Submission 1.0.
4
How can I fix CVE-2025-8271?
To fix CVE-2025-8271, you should validate and sanitize user inputs for SQL queries in the affected code.
5
Is CVE-2025-8271 remotely exploitable?
Yes, CVE-2025-8271 can be exploited remotely.