A vulnerability was identified in CodeAstro Student Grading System 1.0. This issue affects some unknown processing of the file /adminLogin.php. Such manipulation of the argument staffId leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
History

Fri, 03 Oct 2025 13:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:codeastro:student_grading_system:1.0:*:*:*:*:*:*:*

Mon, 29 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Sep 2025 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Codeastro
Codeastro student Grading System
Vendors & Products Codeastro
Codeastro student Grading System

Sun, 28 Sep 2025 20:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in CodeAstro Student Grading System 1.0. This issue affects some unknown processing of the file /adminLogin.php. Such manipulation of the argument staffId leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
Title CodeAstro Student Grading System adminLogin.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-09-28T20:02:06.183Z

Updated: 2025-09-29T14:46:56.033Z

Reserved: 2025-09-27T17:41:26.605Z

Link: CVE-2025-11118

cve-icon Vulnrichment

Updated: 2025-09-29T14:46:42.725Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-28T20:15:47.570

Modified: 2025-10-03T13:39:40.880

Link: CVE-2025-11118

cve-icon Redhat

No data.