📦 Student Information System

by Fabian

🔍 What is Student Information System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-15053

HIGH CVSS 7.3 Dec 24, 2025

This SQL injection vulnerability in code-projects Student Information System 1.0 allows attackers to manipulate database queries through the searchbox parameter in searchresults.php. Attackers can pot...

CVE-2025-13242

HIGH CVSS 7.3 Nov 16, 2025

This SQL injection vulnerability in Student Information System 2.0 allows attackers to execute arbitrary SQL commands through the /register.php endpoint. Remote attackers can potentially access, modif...

CVE-2025-13241

HIGH CVSS 7.3 Nov 16, 2025

CVE-2025-13241 is an SQL injection vulnerability in code-projects Student Information System 2.0 that allows remote attackers to execute arbitrary SQL commands via the Username parameter in /index.php...

CVE-2025-13240

HIGH CVSS 7.3 Nov 16, 2025

CVE-2025-13240 is an SQL injection vulnerability in code-projects Student Information System 2.0 that allows attackers to manipulate database queries through the 's' parameter in /searchquery.php. Thi...

CVE-2025-13244

MEDIUM CVSS 4.3 Nov 16, 2025

This vulnerability allows attackers to inject malicious scripts into the Student Information System 2.0 registration page, which could execute in victims' browsers when they visit the compromised page...

CVE-2025-13243

MEDIUM CVSS 6.3 Nov 16, 2025

This SQL injection vulnerability in code-projects Student Information System 2.0 allows attackers to execute arbitrary SQL commands through the /editprofile.php endpoint. Any organization using this s...

CVE-2025-15052

LOW CVSS 3.5 Dec 24, 2025

This stored cross-site scripting (XSS) vulnerability in code-projects Student Information System 1.0 allows attackers to inject malicious scripts into firstname/lastname fields in profile.php. When ot...

CVE-2025-13245

LOW CVSS 3.5 Nov 16, 2025

This vulnerability allows attackers to inject malicious scripts into the Student Information System 2.0 through the /editprofile.php page. When exploited, it enables cross-site scripting attacks that ...