CVE-2025-66947

MEDIUM

krishanmurariji student_management_system 1.0 - SQL Injection via editid GET Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-66947. PoCs published by kabir0104k.

AI-analyzed exploit summary This repository provides a detailed writeup and proof-of-concept for a time-based blind SQL injection vulnerability (CVE-2025-66947) in krishanmuraiji SMS v1.0. The vulnerability exists in the `editid` parameter of the `/studentms/admin/edit-class-detail.php` endpoint, allowing attackers to inject malicious SQL payloads that cause measurable delays in server responses.

Description

SQL injection vulnerability in krishanmuraiji SMS v.1.0, within the /studentms/admin/edit-class-detail.php via the editid GET parameter. An attacker can trigger controlled delays using SQL SLEEP() to infer database contents. Successful exploitation may lead to full database compromise, especially within an administrative module.

Exploits (1)

nomisec WRITEUP 1 stars
by kabir0104k · poc
https://github.com/kabir0104k/CVE-2025-66947

This repository provides a detailed writeup and proof-of-concept for a time-based blind SQL injection vulnerability (CVE-2025-66947) in krishanmuraiji SMS v1.0. The vulnerability exists in the `editid` parameter of the `/studentms/admin/edit-class-detail.php` endpoint, allowing attackers to inject malicious SQL payloads that cause measurable delays in server responses.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: krishanmuraiji SMS v1.0
Auth required
Prerequisites: Access to the admin panel · Valid session or authentication credentials
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0026
EPSS Percentile 17.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
krishanmurariji/student_management_system 1.0
Published Dec 26, 2025
Tracked Since Feb 18, 2026