Institute-of-Current-Students v1.0 contains a time-based blind SQL injection vulnerability in the mydetailsstudent.php endpoint. The myds GET parameter is not adequately sanitized before being used in SQL queries.
myds
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-52410.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "1.0" } ] } ]