CVE-2025-14336: itsourcecode Student Management System promote.php sql injection
Published Dec 9, 2025
·Updated
A vulnerability was found in itsourcecode Student Management System 1.0. Affected by this issue is some unknown functionality of the file /promote.php. The manipulation of the argument sy results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Affected Software
2 affected components
itsourcecode Student Management System
Angeljudesuarez Student Management System=1.0
Event History
Dec 9, 2025
CVE Published
via MITRE·07:02 PM
Data Sourced
via MITRE·07:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-14336?
CVE-2025-14336 has a severe impact due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2025-14336?
To mitigate CVE-2025-14336, validate and sanitize all user inputs in the /promote.php file.
3
What type of vulnerability is CVE-2025-14336?
CVE-2025-14336 is categorized as an SQL injection vulnerability.
4
What software is affected by CVE-2025-14336?
CVE-2025-14336 affects itsourcecode Student Management System version 1.0.
5
Can CVE-2025-14336 be exploited remotely?
Yes, CVE-2025-14336 can be exploited remotely, allowing attackers to execute SQL injection from outside the system.