CVE-2025-11434: itsourcecode Student Transcript Processing System login.php sql injection
A weakness has been identified in itsourcecode Student Transcript Processing System 1.0. Affected is an unknown function of the file /login.php. Executing a manipulation of the argument uname can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11434?
CVE-2025-11434 has been classified as a high severity vulnerability due to the potential for SQL injection attacks.
How can I fix CVE-2025-11434?
To remediate CVE-2025-11434, sanitize and validate all user inputs, particularly the 'uname' parameter in /login.php.
What systems are affected by CVE-2025-11434?
CVE-2025-11434 affects itsourcecode Student Transcript Processing System version 1.0.
Can CVE-2025-11434 be exploited remotely?
Yes, CVE-2025-11434 can be exploited remotely by manipulating the 'uname' parameter.
What type of attack can occur due to CVE-2025-11434?
CVE-2025-11434 can lead to SQL injection attacks, compromising the database security.