PT-2025-47602 · Unknown · Institute-Of-Current-Students

Published

2025-11-20

·

Updated

2025-11-21

·

CVE-2025-52410

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Institute-of-Current-Students version 1.0
Description The software contains a time-based blind SQL injection issue in the ''mydetailsstudent.php'' endpoint. The myds GET parameter is not properly sanitized before use in SQL queries, potentially allowing for malicious data injection.
Recommendations Ensure proper sanitization of the myds GET parameter in the ''mydetailsstudent.php'' endpoint to prevent SQL injection attacks.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-52410

Affected Products

Institute-Of-Current-Students