PT-2025-39668 · Kidaze · Courseselectionsystem

Liming0618

·

Published

2025-09-26

·

Updated

2025-09-26

·

CVE-2025-11032

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions kidaze CourseSelectionSystem versions prior to 42cd892b40a18d50bd4ed1905fa89f939173a464
Description A flaw exists in kidaze CourseSelectionSystem that allows for SQL injection. The issue stems from the manipulation of the CPU argument during processing of the file '/Profilers/PriProfile/COUNT3s6.php'. This can be exploited remotely.
Recommendations Update kidaze CourseSelectionSystem to a version prior to 42cd892b40a18d50bd4ed1905fa89f939173a464.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-11032

Affected Products

Courseselectionsystem