A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/save_user.php. This manipulation of the argument firstname causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. Other parameters might be affected as well.
References
| Link | Resource |
|---|---|
| https://github.com/qcycop0101-hash/CVE/issues/12 | Exploit Issue Tracking Third Party Advisory |
| https://vuldb.com/?ctiid.323918 | Permissions Required VDB Entry |
| https://vuldb.com/?id.323918 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.648597 | Third Party Advisory VDB Entry |
| https://www.sourcecodester.com/ | Product |
| https://github.com/qcycop0101-hash/CVE/issues/12 | Exploit Issue Tracking Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-09-15 23:15
Updated : 2025-09-22 17:07
NVD link : CVE-2025-10483
Mitre link : CVE-2025-10483
CVE.ORG link : CVE-2025-10483
JSON object : View
Products Affected
janobe
- online_student_file_management_system
