Vulnerability Description
A weakness has been identified in code-projects Question Paper Generator 1.0. This affects an unknown part of the file /signupscript.php of the component POST Parameter Handler. Executing manipulation of the argument Fname can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Carmelo | Question Paper Generator | 1.0 |
Related Weaknesses (CWE)
References
- https://code-projects.org/Product
- https://github.com/rassec2/dbcve/issues/6ExploitIssue TrackingThird Party Advisory
- https://vuldb.com/?ctiid.333347Permissions RequiredVDB Entry
- https://vuldb.com/?id.333347Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.699591Third Party AdvisoryVDB Entry
FAQ
What is CVE-2025-13583?
CVE-2025-13583 is a vulnerability with a CVSS score of 7.3 (HIGH). A weakness has been identified in code-projects Question Paper Generator 1.0. This affects an unknown part of the file /signupscript.php of the component POST Parameter Handler. Executing manipulation...
How severe is CVE-2025-13583?
CVE-2025-13583 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-13583?
Check the references section above for vendor advisories and patch information. Affected products include: Carmelo Question Paper Generator.