CVE-2025-8271
HIGHCode-projects Exam Form Submission - Injection
Title source: ruleDescription
A vulnerability was found in code-projects Exam Form Submission 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/delete_s3.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
References (5)
Scores
CVSS v3
7.3
EPSS
0.0004
EPSS Percentile
12.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-74
CWE-89
Status
published
Affected Products (1)
code-projects/exam_form_submission
Timeline
Published
Jul 28, 2025
Tracked Since
Feb 18, 2026