Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 23 Feb 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fabian
Fabian scholars Tracking System |
|
| CPEs | cpe:2.3:a:fabian:scholars_tracking_system:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Fabian
Fabian scholars Tracking System |
Thu, 19 Feb 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Code-projects
Code-projects scholars Tracking System |
|
| Vendors & Products |
Code-projects
Code-projects scholars Tracking System |
Wed, 18 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
ssvc
|
Wed, 18 Feb 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters (firstname, lastname, username, password, user_id) into SQL queries without validation or parameterization. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-18T18:06:19.419Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-70152
Updated: 2026-02-18T18:06:04.741Z
Status : Analyzed
Published: 2026-02-18T18:24:21.530
Modified: 2026-02-23T17:54:31.543
Link: CVE-2025-70152
No data.
OpenCVE Enrichment
Updated: 2026-02-19T10:20:40Z