The Faculty Evaluation System Project maintains a specialized academic assessment platform that, despite serving a focused institutional use case, carries a durable profile of serious input-handling and injection vulnerabilities. Vulnerabilities affecting this product skew strongly toward critical severity and frequently acquire public exploit code, reflecting the exposure of web-facing input surfaces to SQL injection, code injection, cross-site scripting, and unsafe file uploads. Defenders should prioritize patches for this product where it is deployed in educational environments and restrict direct internet exposure; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Faculty Evaluation System Project over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-33440HIGH Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user. | May 26, 2023 | 7.2 | 47 | NO | YES |
CVE-2023-33439HIGH Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_task.php?id=. | May 26, 2023 | 7.2 | 33 | NO | YES |
CVE-2023-2365CRITICAL A vulnerability has been found in SourceCodester Faculty Evaluation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file aj | Apr 28, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-2368CRITICAL A vulnerability was found in SourceCodester Faculty Evaluation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file index.php?page=mana | Apr 28, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-2367CRITICAL A vulnerability was found in SourceCodester Faculty Evaluation System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/manage_academic.php. | Apr 28, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-2366CRITICAL A vulnerability was found in SourceCodester Faculty Evaluation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file ajax.php?acti | Apr 28, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-2962CRITICAL A vulnerability, which was classified as critical, has been found in SourceCodester Faculty Evaluation System 1.0. Affected by this issue is some unknown functionality of the file | May 29, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-2369CRITICAL A vulnerability was found in SourceCodester Faculty Evaluation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/manage_restri | Apr 28, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-31845HIGH Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_class.php?id=. | May 15, 2023 | 7.2 | 23 | NO | NO |
CVE-2023-31844HIGH Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_subject.php?id=. | May 15, 2023 | 7.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Faculty Evaluation System Project.
Media articles that mention a CVE ID that affects a product developed by Faculty Evaluation System Project — matched by CVE ID, not by vendor name.