VulnerabilityAnalyzed
CVE-2025-9610
A vulnerability was determined in code-projects Online Event Judging System 1.0.
MEDIUM 5.5EPSS 0.42%
Does this matter?
Lower severity and a low EPSS score (0.42%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was determined in code-projects Online Event Judging System 1.0. This issue affects some unknown processing of the file /create_account.php. This manipulation of the argument fname causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Other parameters might be affected as well.
- CVSS 4.0
- 5.5 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.42% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-89
- Affected
- carmelo/online event judging system
- Source
- cna@vuldb.com
References
- https://code-projects.org/Product
- https://github.com/yihaofuweng/cve/issues/15Exploit, Issue Tracking
- https://vuldb.com/?ctiid.321788Permissions Required, VDB Entry
- https://vuldb.com/?id.321788Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.636622Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.