PT-2025-52449 · Code Projects · Scholars Tracking System

·

CVE-2025-14951

·

Published

2025-12-19

·

Updated

2025-12-19

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Scholars Tracking System version 1.0
Description A security issue exists in code-projects Scholars Tracking System 1.0. Manipulation of the post content argument within a file, /home.php, can lead to SQL injection. This issue is remotely exploitable and has been publicly disclosed. The vulnerable element is an unknown function within the /home.php file.
Recommendations Apply any available updates to address the SQL injection issue in the /home.php file. As a temporary workaround, consider restricting or sanitizing the post content argument to prevent SQL injection attacks.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-14951

Affected Products

Scholars Tracking System