CVE-2025-8494: code-projects Intern Membership Management System delete_student.php sql injection
A vulnerability, which was classified as critical, has been found in code-projects Intern Membership Management System 1.0. This issue affects some unknown processing of the file /admin/deletestudent.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8494?
CVE-2025-8494 has been classified as a critical vulnerability.
How does CVE-2025-8494 affect the Intern Membership Management System?
CVE-2025-8494 allows for SQL injection through the manipulation of the ID argument in the file /admin/delete_student.php.
How do I fix CVE-2025-8494?
To mitigate CVE-2025-8494, sanitize all user inputs to prevent SQL injection and consider upgrading to a patched version of the software.
What are the potential impacts of exploiting CVE-2025-8494?
Exploitation of CVE-2025-8494 could allow an attacker to manipulate the database and execute arbitrary SQL commands.
Is CVE-2025-8494 specific to certain versions of the software?
CVE-2025-8494 affects version 1.0 of Code-projects Intern Membership Management System.