PT-2025-21573 · Sourcecodester · Sourcecodester Student Management System

Me1Ody

·

Published

2025-05-15

·

Updated

2025-05-27

·

CVE-2025-4720

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions: SourceCodester Student Result Management System version 1.0
Description: A critical issue was found in the system, affecting the file academic/core/drop student.php. The manipulation of the img argument leads to path traversal. This issue can be exploited remotely.
Recommendations: For SourceCodester Student Result Management System version 1.0, consider restricting access to the drop student.php file until a patch is available. As a temporary workaround, avoid using the img argument in the affected file to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-4720

Affected Products

Sourcecodester Student Management System