PT-2025-24012 · Unknown · Sourcecodester Student Management System
Eric Tee
·
Published
2025-06-06
·
Updated
2025-06-06
·
CVE-2025-5723
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SourceCodester Student Result Management System version 1.0
Description
A vulnerability was found in the SourceCodester Student Result Management System, classified as problematic. This issue affects some unknown processing of the file "/script/academic/classes" of the component Classes Page. The manipulation of the argument
Class Name leads to cross-site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.Recommendations
For SourceCodester Student Result Management System version 1.0, consider disabling the
Class Name argument in the "/script/academic/classes" file to minimize the risk of exploitation until a patch is available. Restrict access to the Classes Page to prevent remote attacks.Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sourcecodester Student Management System