A vulnerability described as critical has been identified in code-projects Student File Management System 1.0. This vulnerability affects unknown code of the file /admin/save_user.php. The manipulation of the argument firstname results in sql injection.
This vulnerability is identified as CVE-2025-14622. The attack can be executed remotely. Additionally, an exploit exists.