First published: Tue Dec 08 2020(Updated: )
SourceCodester Student Management System Project in PHP version 1.0 is vulnerable to stored a cross-site scripting (XSS) via the 'add subject' tab.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Student Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25955 is classified as a moderate severity vulnerability due to its potential to allow attackers to execute malicious scripts.
To fix CVE-2020-25955, developers should sanitize and properly validate user input in the 'add subject' tab of the Student Management System.
CVE-2020-25955 affects version 1.0 of the Student Management System Project in PHP.
CVE-2020-25955 is a stored cross-site scripting (XSS) vulnerability.
Yes, CVE-2020-25955 can be exploited remotely by an attacker who can inject malicious scripts through the vulnerable interface.