CVE-2025-10479: SourceCodester Online Student File Management System index.php sql injection
A security flaw has been discovered in SourceCodester Online Student File Management System 1.0. The impacted element is an unknown function of the file /index.php. Performing manipulation of the argument studno results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10479?
CVE-2025-10479 is classified as a high severity SQL injection vulnerability.
How do I fix CVE-2025-10479?
To fix CVE-2025-10479, sanitize and validate the input for the stud_no parameter to prevent SQL injection.
Can CVE-2025-10479 be exploited remotely?
Yes, CVE-2025-10479 can be exploited remotely by manipulating the stud_no parameter.
What software is affected by CVE-2025-10479?
CVE-2025-10479 affects SourceCodester Online Student File Management System version 1.0.
What type of attack is enabled by CVE-2025-10479?
CVE-2025-10479 enables an SQL injection attack due to improper handling of user input.