Record summary

CVE-2025-6403 has a selected CVSS score of 6.9 (medium); EIP currently links 1 Nuclei template.

Description

A vulnerability was found in code-projects School Fees Payment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /student.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 27, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 23, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List1.0affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALCode-Projects School Fees Payment System 1.0 - SQL InjectionCVSS 9.8

A vulnerability was found in code-projects School Fees Payment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /student.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Impact

Remote attackers can execute arbitrary SQL commands, potentially leading to data theft or modification.

Remediation

Update to the latest version.

WeaknessesCWE-74
Authorshnd3884
Template tagscvecve2025sqlicode_projectsunauthschool_fees_payment_systemtime-basedvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:code-projects:school_fees_payment_system:1.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

6