PT-2025-37775 · Sourcecodester · Online Student Management System

·

CVE-2025-10483

·

Published

2025-09-15

·

Updated

2025-09-16

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Online Student File Management System version 1.0
Description A SQL injection flaw exists due to the manipulation of the firstname argument in the /admin/save user.php file. This manipulation can be carried out remotely. The exploit has been published. Other parameters might also be affected.
Recommendations As a temporary workaround, consider restricting access to the /admin/save user.php file to minimize the risk of exploitation. Sanitize the firstname parameter before using it in SQL queries. Review and sanitize all other parameters used in the /admin/save user.php file to prevent potential SQL injection vulnerabilities.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10483

Affected Products

Online Student Management System