SQL injection vulnerability in krishanmuraiji SMS v.1.0, within the /studentms/admin/edit-class-detail.php via the editid GET parameter. An attacker can trigger controlled delays using SQL SLEEP() to infer database contents. Successful exploitation may lead to full database compromise, especially within an administrative module.
Metrics
Affected Vendors & Products
References
History
Fri, 26 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Fri, 26 Dec 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection vulnerability in krishanmuraiji SMS v.1.0, within the /studentms/admin/edit-class-detail.php via the editid GET parameter. An attacker can trigger controlled delays using SQL SLEEP() to infer database contents. Successful exploitation may lead to full database compromise, especially within an administrative module. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-26T16:31:09.014Z
Reserved: 2025-12-08T00:00:00.000Z
Link: CVE-2025-66947
Updated: 2025-12-26T16:31:05.282Z
Status : Received
Published: 2025-12-26T15:15:47.700
Modified: 2025-12-26T17:15:44.403
Link: CVE-2025-66947
No data.
OpenCVE Enrichment
No data.