External risk intelligence

Scholars Tracking System 1.0 SQL Injection in Admin User Management.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-70152

The vulnerability exists in a web application's administrative endpoints. Such web-based management interfaces for tracking systems are commonly deployed as web-accessible services, making these specific administrative endpoints potentially reachable if the application is hosted on an internet-facing web server.

SQL Injection

Fabian Scholars Tracking System

1.0

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the Community Project Scholars Tracking System, specifically in its administrative user management functions. This issue allows for unauthorized access and manipulation of data due to improper handling of user inputs within database queries. The primary concern is to determine if this system is in use and potentially exposed.

  • Unauthenticated users can alter user records.
  • Critical vulnerability in administrative functions.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can target the Scholars Tracking System by sending specially crafted requests to specific administrative endpoints. These endpoints, designed for managing users, do not require any authentication. By manipulating parameters sent in these requests, an attacker can inject malicious SQL code, which the system then executes. This allows for unauthorized data access, modification, or deletion.

  • No authentication needed for admin endpoints.
  • User-supplied data directly in SQL queries.
  • Risk of unauthorized data access and modification.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to inject malicious SQL commands into the Scholars Tracking System. This could lead to unauthorized access to, modification of, or deletion of sensitive user and system data managed by the application, and potentially disrupt its normal operation.

  • User and system data.
  • Via unauthenticated administrative endpoints.
  • Unauthorized data access and modification.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Scholars Tracking System, specifically the admin user management endpoints, is susceptible to SQL injection due to unvalidated POST parameters. Teams responsible for managing the application's infrastructure and the application itself should prioritize identifying all instances of this system, confirming network exposure and business criticality, and assigning an owner for remediation planning.

  • Application owners should confirm exposure.
  • Verify unauthenticated admin access is blocked.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Scholars Tracking System?

The Scholars Tracking System is a PHP-based web application developed as a community project, designed to help organizations manage and record details about students or scholars. It provides a central interface for administrative tasks, such as maintaining user profiles, which are managed through specific web pages within the application.

What does SQL injection mean for CVE-2025-70152?

This CVE involves a weakness classified as CWE-89, or Improper Neutralization of Special Elements used in an SQL Command. In plain terms, the software takes information provided by a user and inserts it directly into database commands without checking it. An attacker can use this to 'inject' their own malicious instructions, tricking the database into revealing, changing, or deleting information it should keep secure.

How is this SQL injection triggered?

The vulnerability is triggered by sending specially crafted web requests to the admin user management endpoints. Because these endpoints lack authentication, an attacker does not need a login or password to interact with them. Simply browsing to the page will not trigger the bug; the attacker must intentionally send a POST request containing malicious data in specific fields like username or password.

Do I need to worry if my system is internal?

According to Halo Surface Signal, this vulnerability is particularly risky because administrative web interfaces are often hosted on servers accessible to wider networks. While the risk is highest if the application is internet-facing, any internal user—or any compromise within your network—could reach these unauthenticated endpoints to manipulate your database.

What are the first steps to address this?

Your priority is to locate all instances of the Scholars Tracking System within your environment. Once identified, ensure these administrative endpoints are no longer reachable by unauthorized users, such as by restricting network access or blocking traffic to the vulnerable /admin/ files. Finally, document the system's business use to help prioritize further remediation.

References