CVE-2026-3745: code-projects Student Web Portal profile.php sql injection
A vulnerability was found in code-projects Student Web Portal 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument User results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3745?
CVE-2026-3745 has a high severity rating due to its SQL injection vulnerability.
How do I fix CVE-2026-3745?
To fix CVE-2026-3745, sanitize and validate user inputs in the profile.php file to prevent SQL injection attacks.
Can CVE-2026-3745 be exploited remotely?
Yes, CVE-2026-3745 can be exploited remotely by manipulating the user argument in the profile.php file.
What types of attacks can CVE-2026-3745 lead to?
CVE-2026-3745 can lead to unauthorized data access and potential database manipulation due to SQL injection.
Which software is affected by CVE-2026-3745?
CVE-2026-3745 affects Version 1.0 of the Code-projects Student Web Portal.