CVE-2025-15034: itsourcecode Student Management System record.php sql injection
A security flaw has been discovered in itsourcecode Student Management System 1.0. This affects an unknown part of the file /record.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15034?
CVE-2025-15034 has been classified as a high severity vulnerability due to its potential for remote exploitation through SQL injection.
How do I fix CVE-2025-15034?
To fix CVE-2025-15034, sanitize all user inputs in the /record.php file to prevent SQL injection attacks.
What are the implications of CVE-2025-15034?
CVE-2025-15034 can allow attackers to manipulate database queries, potentially leading to data breaches or unauthorized access.
Who is affected by CVE-2025-15034?
All users of itsourcecode Student Management System version 1.0 are affected by CVE-2025-15034.
When was CVE-2025-15034 disclosed?
CVE-2025-15034 was publicly disclosed following the release of the exploit, although the specific date of the disclosure is not stated.