Unrated severityNVD Advisory· Published Jul 4, 2026· Updated Jul 6, 2026
code-projects Assessment Management Database Query marking-scheme.php sql injection
CVE-2026-14657
Description
A flaw has been found in code-projects Assessment Management 1.0. This issue affects some unknown processing of the file /lecturer/marking-scheme.php of the component Database Query Handler. This manipulation of the argument squestions[] causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
Patches
Vulnerability mechanics
References
6- github.com/zzzxc643/CVE1/blob/main/assessment/vul5.mdmitreexploit
- vuldb.com/cve/CVE-2026-14657mitrethird-party-advisory
- vuldb.com/submit/846716mitrethird-party-advisory
- code-projects.orgmitreproduct
- vuldb.com/vuln/376172mitrevdb-entrytechnical-description
- vuldb.com/vuln/376172/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.