CVE-2025-9444: 1000projects Online Project Report Submission and Evaluation System delete_group_student.php sql injection
A vulnerability has been found in 1000projects Online Project Report Submission and Evaluation System 1.0. This issue affects some unknown processing of the file /admin/controller/deletegroupstudent.php. The manipulation of the argument batchid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9444?
CVE-2025-9444 is classified as a high severity vulnerability due to its exploitation potential through SQL injection.
How do I fix CVE-2025-9444?
To fix CVE-2025-9444, validate and sanitize input from the batch_id parameter to prevent SQL injection.
What are the potential impacts of exploiting CVE-2025-9444?
Exploiting CVE-2025-9444 could allow attackers to manipulate the database and gain unauthorized access to sensitive data.
Which systems are affected by CVE-2025-9444?
CVE-2025-9444 affects version 1.0 of the 1000projects Online Project Report Submission and Evaluation System.
Is there a patch available for CVE-2025-9444?
As of now, there is no official patch available for CVE-2025-9444, so applying input validation is crucial.