CVE-2025-14214: itsourcecode Student Information System section_edit1.php sql injection
A vulnerability has been found in itsourcecode Student Information System 1.0. This affects an unknown part of the file /sectionedit1.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14214?
CVE-2025-14214 is classified as a critical vulnerability due to the potential for remote SQL injection, which could allow attackers to manipulate database queries.
How do I fix CVE-2025-14214?
To fix CVE-2025-14214, patch the application to sanitize inputs, particularly the 'ID' argument in /section_edit1.php, to prevent SQL injection.
Which versions of itsourcecode Student Information System are affected by CVE-2025-14214?
CVE-2025-14214 affects all versions of itsourcecode Student Information System 1.0.
Can CVE-2025-14214 be exploited remotely?
Yes, CVE-2025-14214 can be exploited remotely by an attacker to perform SQL injection.
What kind of vulnerabilities does CVE-2025-14214 involve?
CVE-2025-14214 involves SQL injection vulnerabilities that allow unauthorized database access and manipulation.