CVE-2025-0800: SourceCodester Online Courseware Edit Teacher saveeditt.php cross site scripting
A vulnerability classified as problematic has been found in SourceCodester Online Courseware 1.0. Affected is an unknown function of the file /pcci/admin/saveeditt.php of the component Edit Teacher. The manipulation of the argument fname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0800?
CVE-2025-0800 has been classified as problematic due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-0800?
To fix CVE-2025-0800, sanitize and validate inputs in the fname argument of the /pcci/admin/saveeditt.php file.
What impact does CVE-2025-0800 have on users?
CVE-2025-0800 allows attackers to execute arbitrary scripts in the context of the user's browser, compromising user data.
Which application is affected by CVE-2025-0800?
CVE-2025-0800 affects the SourceCodester Online Courseware version 1.0.
How can I determine if my installation is vulnerable to CVE-2025-0800?
Check if your installation of SourceCodester Online Courseware includes the /pcci/admin/saveeditt.php file and is utilizing the vulnerable fname argument.