Code-Projects Simple Attendance Record System是Code-Projects开源的一个简易考勤记录系统。 Code-Projects Simple Attendance Record System 2.0版本存在SQL注入漏洞,该漏洞源于对文件/check.php中参数student的错误操作,可能导致SQL注入攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| code-projects | Simple Attendance Record System | 2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-14647 | 7.3 HIGH | code-projects Computer Book Store admin_delete.php sql injection |
| CVE-2025-14646 | 7.3 HIGH | code-projects Student File Management System delete_student.php sql injection |
| CVE-2025-14645 | 7.3 HIGH | code-projects Student File Management System delete_user.php sql injection |
| CVE-2025-14640 | 7.3 HIGH | code-projects Student File Management System save_student.php sql injection |
| CVE-2025-14642 | 4.7 MEDIUM | code-projects Computer Laboratory System technical_staff_pic.php unrestricted upload |
| CVE-2025-14641 | 4.7 MEDIUM | code-projects Computer Laboratory System admin_pic.php unrestricted upload |
| CVE-2025-14663 | 2.4 LOW | code-projects Student File Management System update_student.php cross site scripting |
| CVE-2025-14662 | 2.4 LOW | code-projects Student File Management System Update User update_user.php cross site script |
No comments yet