---
id: CVE-2025-11116
title: A vulnerability was found in code-projects Simple Scheduling System 1.0
summary: >-
  A vulnerability was found in code-projects Simple Scheduling System 1.0. This
  affects an unknown part of the file /add.home.php. The manipulation of the
  argument faculty results in sql injection. The attack can be executed
  remotely. The …
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
vendor: fabian
product: simple_scheduling_system
affected:
  - simple_scheduling_system = 1.0
published: '2025-09-28'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11116'
references:
  - url: 'https://code-projects.org/'
    label: cna@vuldb.com
  - url: 'https://github.com/yihaofuweng/cve/issues/42'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.326197'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.326197'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.662701'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00478
epssPercentile: 0.38937
ingestedAt: '2026-09-30T23:29:32.411Z'
---

## Overview

A vulnerability was found in code-projects Simple Scheduling System 1.0. This affects an unknown part of the file /add.home.php. The manipulation of the argument faculty results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. Other parameters might be affected as well.

## Affected

- `simple_scheduling_system = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
