First published: Wed Jan 29 2025(Updated: )
A vulnerability classified as problematic has been found in SourceCodester Online Courseware 1.0. Affected is an unknown function of the file /pcci/admin/saveeditt.php of the component Edit Teacher. The manipulation of the argument fname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
SourceCodester Online Courseware | ||
argie Online Courseware | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0800 has been classified as problematic due to its potential for cross-site scripting attacks.
To fix CVE-2025-0800, sanitize and validate inputs in the fname argument of the /pcci/admin/saveeditt.php file.
CVE-2025-0800 allows attackers to execute arbitrary scripts in the context of the user's browser, compromising user data.
CVE-2025-0800 affects the SourceCodester Online Courseware version 1.0.
Check if your installation of SourceCodester Online Courseware includes the /pcci/admin/saveeditt.php file and is utilizing the vulnerable fname argument.