PT-2025-19926 · Unknown · Sourcecodester Online Student Clearance System

Esharmaji

·

Published

2025-05-06

·

Updated

2025-09-27

·

CVE-2025-4331

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Online Student Clearance System version 1.0
Description A critical issue was found in the /Admin/login.php file, affecting unknown code. The manipulation of the username and password arguments leads to SQL injection. The attack can be initiated remotely.
Recommendations For SourceCodester Online Student Clearance System version 1.0, consider disabling the login functionality in the /Admin/login.php file until a patch is available to prevent SQL injection attacks. Restrict access to the /Admin/login.php file to minimize the risk of exploitation. Avoid using the username and password arguments in the affected login endpoint until the issue is resolved.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-4331

Affected Products

Sourcecodester Online Student Clearance System