VulnerabilityAnalyzed
CVE-2026-3745
A vulnerability was found in code-projects Student Web Portal 1.0.
LOW 2.1EPSS 0.30%
Does this matter?
Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in code-projects Student Web Portal 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument User results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.30% probability · 23th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-89
- Affected
- carmelo/student web portal
- Source
- cna@vuldb.com
References
- https://code-projects.org/Product
- https://github.com/CH0ico/CVE_choco_4Third Party Advisory
- https://github.com/CH0ico/CVE_choco_4/blob/main/report.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.349723Permissions Required, VDB Entry
- https://vuldb.com/?id.349723Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.767854Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.