PT-2025-38287 · Unknown · Sourcecodester Online Exam Form
Quchunyi1
·
Published
2025-09-17
·
Updated
2025-09-18
·
CVE-2025-10625
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SourceCodester Online Exam Form Submission version 1.0
Description
A SQL injection issue exists due to the manipulation of the
phone argument in the file /user/dashboard.php?page=update profile. The attack can be launched remotely. The exploit is publicly available. Other parameters may also be affected.Recommendations
Sanitize the
phone argument to prevent SQL injection.
Review and sanitize all other input parameters to mitigate potential risks.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sourcecodester Online Exam Form