PT-2025-51143 · Itsourcecode · Student Management System

Mountain Ghost

·

Published

2025-12-14

·

Updated

2025-12-19

·

CVE-2025-14644

CVSS v3.1
9.8
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions itsourcecode Student Management System version 1.0
Description A flaw exists in itsourcecode Student Management System 1.0 that allows for SQL injection. The issue is located in the
/update subject.php
file, specifically through manipulation of the
ID
argument within an unknown function. This allows for remote execution of attacks. The exploit has been publicly disclosed.
Recommendations Apply updates to address the issue in the
/update subject.php
file. As a temporary workaround, restrict access to the
ID
parameter in the
/update subject.php
file.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2025-14644

Affected Products

Student Management System