Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2025-6403

CWE-74CWE-89SQL Injection5 documents5 sources
Severity
6.9MEDIUM
EPSS
0.9%
top 23.78%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJun 21

Description

A vulnerability was found in code-projects School Fees Payment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /student.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages2 packages

🔴Vulnerability Details

3
CVEList
code-projects School Fees Payment System student.php sql injection2025-06-21
GHSA
GHSA-wj7f-45f7-384p: A vulnerability was found in code-projects School Fees Payment System 12025-06-21
VulnCheck
fabian school_fees_payment_system Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2025

💥Exploits & PoCs

1
Nuclei
Code-Projects School Fees Payment System 1.0 - SQL Injection
CVE-2025-6403 (MEDIUM CVSS 6.9) | A vulnerability was found in code-p | cvebase.io