CVE-2025-15196
🟡 Monitoruj
Wstrzyknięcie SQL w code-projects Assessment Management umożliwia zdalne ataki.
CVSS
7.3
EPSS
0.4%
Exploit
poc
Vendor
code-projects
Opis źródłowy (NVD)
A vulnerability was identified in code-projects Assessment Management 1.0. This affects an unknown part of the file login.php. Such manipulation of the argument userid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
exploit sql-injection
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2025-12-29 17:15:44 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-05 19:10:00 UTC |
Referencje
- https://code-projects.org/ ([email protected]) [Product]
- https://github.com/Limingqian123/CVE/issues/4 ([email protected]) [Exploit, Issue Tracking, Third Party Advisory]
- https://vuldb.com/?ctiid.338583 ([email protected]) [Permissions Required, VDB Entry]
- https://vuldb.com/?id.338583 ([email protected]) [Third Party Advisory, VDB Entry]
- https://vuldb.com/?submit.724718 ([email protected]) [Third Party Advisory, VDB Entry]