CVE-2025-14256: itsourcecode Student Management System newcurriculm.php sql injection
Published Dec 8, 2025
·Updated
A vulnerability was detected in itsourcecode Student Management System 1.0. This impacts an unknown function of the file /newcurriculm.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.
Affected Software
2 affected components
itsourcecode Student Management System
Angeljudesuarez Student Management System=1.0
Event History
Dec 8, 2025
CVE Published
via MITRE·04:32 PM
Data Sourced
via MITRE·04:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-14256?
The severity of CVE-2025-14256 is critical due to its potential for SQL injection vulnerabilities.
2
How do I fix CVE-2025-14256?
To fix CVE-2025-14256, input validation and parameterized queries should be implemented in the /newcurriculm.php file.
3
What systems are affected by CVE-2025-14256?
CVE-2025-14256 affects version 1.0 of the itsourcecode Student Management System.
4
Can CVE-2025-14256 be exploited remotely?
Yes, CVE-2025-14256 can be exploited remotely through manipulating the argument ID.
5
What kind of attack is CVE-2025-14256 associated with?
CVE-2025-14256 is associated with SQL injection attacks.