CVE-2025-14258: itsourcecode Student Management System newsubject.php sql injection
A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /newsubject.php. The manipulation of the argument sub leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14258?
CVE-2025-14258 is categorized as a high-severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2025-14258?
To fix CVE-2025-14258, sanitize and validate input parameters in the /newsubject.php file to prevent SQL injection.
What software is affected by CVE-2025-14258?
CVE-2025-14258 affects itsourcecode Student Management System version 1.0.
Can CVE-2025-14258 be exploited remotely?
Yes, CVE-2025-14258 can be exploited remotely through the vulnerable /newsubject.php file.
What type of vulnerability is CVE-2025-14258?
CVE-2025-14258 is an SQL injection vulnerability.