PT-2025-28359 · Unknown · Code-Projects Crime Reporting System

·

CVE-2025-7169

·

Published

2025-07-08

·

Updated

2025-07-08

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: code-projects Crime Reporting System version 1.0
Description: A critical issue has been discovered in the code-projects Crime Reporting System, affecting an unknown function of the /complainer page.php file. The manipulation of the argument location leads to SQL injection, allowing for remote attack execution. The exploit has been publicly disclosed and may be utilized.
Recommendations: For code-projects Crime Reporting System version 1.0, consider disabling the unknown function in the /complainer page.php file as a temporary workaround until a patch is available. Restrict access to the /complainer page.php file to minimize the risk of exploitation. Avoid using the affected function in the complainer page until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-7169

Affected Products

Code-Projects Crime Reporting System