CVE-2025-2392
CVSS 3.1 Score 10 of 10 (high)
Details
Published Mar 17, 2025
CWE ID 352
Summary
CVE-2025-2392 is a critical vulnerability affecting the code-projects Online Class and Exam Scheduling System 1.0. This issue permits an attacker to inject malicious SQL code by manipulating the argument "id" in the processing of the file /pages/activate.php. The exploit can be executed remotely, and the vulnerability has been publicly disclosed, increasing the risk of attacks. Users of this system are advised to apply patches or updates as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.