A vulnerability described as critical has been identified in code-projects Student Information System 2.0. Impacted is an unknown function of the file /editprofile.php. The manipulation results in sql injection.
This vulnerability was named CVE-2025-13243. The attack may be performed from remote. In addition, an exploit is available.