CVE-2025-6403
code-projects School Fees Payment System student.php sql injection
Record summary
CVE-2025-6403 has a selected CVSS score of 6.9 (medium); EIP currently links 1 Nuclei template.
Description
A vulnerability was found in code-projects School Fees Payment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /student.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 27, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 23, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
School Fees Payment SystemBrowse code-projects / School Fees Payment System | CVE List | 1.0 | affected |
school_fees_payment_systemBrowse fabian / school_fees_payment_system | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALCode-Projects School Fees Payment System 1.0 - SQL InjectionCVSS 9.8
A vulnerability was found in code-projects School Fees Payment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /student.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Impact
Remote attackers can execute arbitrary SQL commands, potentially leading to data theft or modification.
Remediation
Update to the latest version.
Source: ProjectDiscovery