
🚨 HIGH: CVE-2025-14640 (CVSS 7.3) SQL injection in Student File Management System 1.0 via /admin/save_student[.]php. Remotely exploitable, exploit public. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/f1MwU6gkQn
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
A flaw has been found in code-projects Student File Management System 1.0. The affected element is an unknown function of the file /admin/save_student.php. Executing manipulation of the argument stud_no can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
NONE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.
1 version affected across 1 product

🚨 HIGH: CVE-2025-14640 (CVSS 7.3) SQL injection in Student File Management System 1.0 via /admin/save_student[.]php. Remotely exploitable, exploit public. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/f1MwU6gkQn
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | fabian | student_file_management_system | 1.0 | - | - |