CVE-2025-14653: itsourcecode Student Management System addrecord.php sql injection
A vulnerability was determined in itsourcecode Student Management System 1.0. Impacted is an unknown function of the file /addrecord.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14653?
CVE-2025-14653 is classified as a high severity vulnerability due to its potential for remote exploitation via SQL injection.
How do I fix CVE-2025-14653?
To fix CVE-2025-14653, sanitize and validate all user input in the /addrecord.php file to prevent SQL injection.
What systems are affected by CVE-2025-14653?
CVE-2025-14653 affects version 1.0 of the itsourcecode Student Management System.
Can CVE-2025-14653 be exploited remotely?
Yes, CVE-2025-14653 can be exploited remotely, allowing attackers to manipulate the ID argument for SQL injection.
What are the potential impacts of CVE-2025-14653?
The potential impacts of CVE-2025-14653 include data exposure and unauthorized manipulation of the database due to SQL injection.