CVE-2025-11601: SourceCodester Online Student Result System login.php sql injection
A vulnerability was detected in SourceCodester Online Student Result System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. Performing manipulation of the argument Username results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11601?
CVE-2025-11601 is classified as a high severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2025-11601?
To fix CVE-2025-11601, validate and sanitize user inputs in the login functionality to prevent SQL injection.
What systems are affected by CVE-2025-11601?
CVE-2025-11601 affects SourceCodester Online Student Result System version 1.0.
Can CVE-2025-11601 be exploited remotely?
Yes, CVE-2025-11601 can be exploited remotely through the login page by manipulating the Username argument.
What type of attacks are possible with CVE-2025-11601?
CVE-2025-11601 allows attackers to perform SQL injection attacks which can lead to unauthorized access or data manipulation.