A vulnerability was identified in kidaze...
Moderate severity
Unreviewed
Published
Dec 12, 2025
to the GitHub Advisory Database
•
Updated Dec 12, 2025
Description
Published by the National Vulnerability Database
Dec 12, 2025
Published to the GitHub Advisory Database
Dec 12, 2025
Last updated
Dec 12, 2025
A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affected element is an unknown function of the file /Profilers/SProfile/login1.php. Such manipulation of the argument Username leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
References