PT-2025-38221 · Kidaze · Courseselectionsystem
Shang
·
Published
2025-09-17
·
Updated
2025-09-17
·
CVE-2025-10597
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
kidaze CourseSelectionSystem versions prior to 42cd892b40a18d50bd4ed1905fa89f939173a464
Description
A vulnerability exists in kidaze CourseSelectionSystem. The issue involves SQL injection caused by manipulation of the
cname argument in the file /Profilers/PriProfile/COUNT2.php. The attack can be initiated remotely. The product uses a rolling release model, and specific version information for affected or updated releases is not available.Recommendations
Versions prior to 42cd892b40a18d50bd4ed1905fa89f939173a464: Restrict or disable access to the
/Profilers/PriProfile/COUNT2.php file.
Versions prior to 42cd892b40a18d50bd4ed1905fa89f939173a464: Sanitize the cname argument to prevent SQL injection.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Courseselectionsystem