CVE-2025-15078: itsourcecode Student Management System list_report.php sql injection
A vulnerability was detected in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /listreport.php. The manipulation of the argument sy results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15078?
CVE-2025-15078 has been classified as a high severity vulnerability due to its potential for remote SQL injection.
How do I fix CVE-2025-15078?
To fix CVE-2025-15078, you should validate and sanitize all user inputs and update the Student Management System to the latest version.
What type of attack is associated with CVE-2025-15078?
CVE-2025-15078 is associated with SQL injection attacks that can be conducted remotely.
Which software is affected by CVE-2025-15078?
CVE-2025-15078 affects the itsourcecode Student Management System version 1.0.
Can CVE-2025-15078 be exploited remotely?
Yes, CVE-2025-15078 can be exploited remotely, allowing attackers to manipulate SQL queries.