📦 Student File Management System

by Fabian

🔍 What is Student File Management System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-14645

HIGH CVSS 7.3 Dec 14, 2025

This SQL injection vulnerability in code-projects Student File Management System 1.0 allows attackers to execute arbitrary SQL commands via the user_id parameter in /admin/delete_user.php. Remote atta...

CVE-2025-14646

HIGH CVSS 7.3 Dec 14, 2025

This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'stud_id' parameter in the /admin/delete_student.php file in code-projects Student File Management System 1.0. This...

CVE-2025-14640

HIGH CVSS 7.3 Dec 14, 2025

This vulnerability allows remote attackers to execute SQL injection attacks against the Student File Management System 1.0 by manipulating the stud_no parameter in the /admin/save_student.php file. Th...

CVE-2025-14622

HIGH CVSS 7.3 Dec 13, 2025

This SQL injection vulnerability in code-projects Student File Management System 1.0 allows attackers to execute arbitrary SQL commands through the firstname parameter in /admin/save_user.php. The vul...

CVE-2025-14623

HIGH CVSS 7.3 Dec 13, 2025

This SQL injection vulnerability in code-projects Student File Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the stud_id parameter in /admin/update_student.php. T...

CVE-2025-14621

HIGH CVSS 7.3 Dec 13, 2025

This SQL injection vulnerability in code-projects Student File Management System 1.0 allows attackers to manipulate database queries through the user_id parameter in /admin/update_user.php. Remote att...

CVE-2025-14619

HIGH CVSS 7.3 Dec 13, 2025

This vulnerability allows remote attackers to execute SQL injection attacks via the 'stud_no' parameter in the login_query.php file of Student File Management System 1.0. Attackers can potentially acc...

CVE-2025-14620

HIGH CVSS 7.3 Dec 13, 2025

CVE-2025-14620 is an SQL injection vulnerability in code-projects Student File Management System 1.0 that allows attackers to manipulate database queries via the Username parameter in /admin/login_que...

CVE-2025-15213

MEDIUM CVSS 4.3 Dec 30, 2025

This vulnerability in Student File Management System 1.0 allows attackers to bypass authorization controls when downloading files via the /download.php endpoint. By manipulating the store_id parameter...

CVE-2025-15205

MEDIUM CVSS 6.3 Dec 29, 2025

CVE-2025-15205 is an SQL injection vulnerability in code-projects Student File Management System 1.0 affecting the /download.php file via the istore_id parameter. This allows remote attackers to execu...

CVE-2025-15050

MEDIUM CVSS 6.3 Dec 24, 2025

This vulnerability allows remote attackers to upload arbitrary files to the Student File Management System 1.0 via the /save_file.php endpoint. Attackers can potentially upload malicious files like we...

CVE-2025-14662

LOW CVSS 2.4 Dec 14, 2025

This vulnerability allows attackers to inject malicious scripts into the Student File Management System's update user page. When exploited, it enables cross-site scripting attacks that could steal ses...

CVE-2025-14663

LOW CVSS 2.4 Dec 14, 2025

This vulnerability allows attackers to inject malicious scripts into the Student File Management System 1.0 through the /admin/update_student.php endpoint. When exploited, it enables cross-site script...