← Vulnerability feed

Vulnerability record · CVE-2024-7681 · published 12 August 2024

CVE-2024-7681: College management system project college management system sql injection vulnerability

CCollege Management System Project · College Management System

A vulnerability was found in code-projects College Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php of the component Login Page. The manipulation of the argument email/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

6.9 CVSS 4.0 Medium EPSS 0.73% · top 47.5% CWE-89 · SQL injection
6.9CVSS 4.0 base score, v2 7.5
0.73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in code-projects College Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php of the component Login Page. The manipulation of the argument email/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/space-security/cve/issues/6 ExploitIssue Tracking
https://vuldb.com/?ctiid.274138 Permissions RequiredThird Party AdvisoryVDB Entry
https://vuldb.com/?id.274138 Permissions RequiredThird Party AdvisoryVDB Entry
https://vuldb.com/?submit.389158 Third Party AdvisoryVDB Entry

Track CVE-2024-7681 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-39180College management system project college management system sql injection vulnerabilityCollege Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in the login.php pageEPSS 0.64%9.8CVE-2020-25409College management system project college management system sql injection vulnerabilityProjectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters.EPSS 1.6%9.8CVE-2020-26051College management system project college management system sql injection vulnerabilityCollege Management System Php 1.0 suffers from SQL injection vulnerabilities in the index.php page from POST parameters 'unametxt' and 'pwdtxt', whic…EPSS 2.4%8.8CVE-2022-32420College management system project college management system vulnerabilityCollege Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /College/admin/teacher.php. This vulnerabili…EPSS 20%8.8CVE-2022-28079College management system project college management system sql injection vulnerabilityCollege Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.EPSS 29%7.2CVE-2022-39179College management system project college management system sql injection vulnerabilityCollege Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that ment…EPSS 1.1%7.2CVE-2022-30404College management system project college management system sql injection vulnerabilityCollege Management System v1.0 is vulnerable to SQL Injection via /College_Management_System/admin/display-teacher.php?teacher_id=.EPSS 0.80%6.5CVE-2020-25408College management system project college management system cross-site request forgery vulnerabilityA Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows a remote attacker to modify, …EPSS 0.78%

Source: NIST National Vulnerability Database (record CVE-2024-7681), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.