scholars_tracking_system vulnerabilities
CVEs whose affected-version data names the scholars_tracking_system package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-70152Critical· 9.8PoCcode-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php
code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly c…
▾ Abyssalfabian · scholars_tracking_systemEPSS 0.45%via NVD
CVE-2025-70151High· 8.8PoCcode-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload
code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-acce…
▾ Midnightfabian · scholars_tracking_systemEPSS 0.70%via NVD