Vulnerability Description
code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters (firstname, lastname, username, password, user_id) into SQL queries without validation or parameterization.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fabian | Scholars Tracking System | 1.0 |
Related Weaknesses (CWE)
References
- https://code-projects.org/scholars-tracking-system-in-php-with-source-code/Product
- https://youngkevinn.github.io/posts/CVE-2025-70152-Scholars-SQLi-Missing-Auth/ExploitThird Party AdvisoryMitigation
FAQ
What is CVE-2025-70152?
CVE-2025-70152 is a vulnerability with a CVSS score of 9.8 (CRITICAL). code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack...
How severe is CVE-2025-70152?
CVE-2025-70152 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-70152?
Check the references section above for vendor advisories and patch information. Affected products include: Fabian Scholars Tracking System.