PT-2025-38223 · Itsourcecode · Web-Based Internet Laboratory Management System

Drewbyte

·

Published

2025-09-17

·

Updated

2025-09-17

·

CVE-2025-10599

CVSS v3.1
7.3
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0. Impacted is the function User::AuthenticateUser of the file login.php. Performing manipulation of the argument user email results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-10599

Affected Products

Web-Based Internet Laboratory Management System