CVE-2025-15196

🟡 Monitoruj

Wstrzyknięcie SQL w code-projects Assessment Management umożliwia zdalne ataki.

CVSS
7.3
EPSS
0.4%
Exploit
poc
Vendor
code-projects
Opis źródłowy (NVD)

A vulnerability was identified in code-projects Assessment Management 1.0. This affects an unknown part of the file login.php. Such manipulation of the argument userid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

exploit sql-injection Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2025-12-29 17:15:44 UTC
Ostatnia modyfikacja (NVD)2026-10-05 19:10:00 UTC
Referencje