CVE-2025-15168: itsourcecode Student Management System statistical.php sql injection
A vulnerability was identified in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /statistical.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15168?
The severity of CVE-2025-15168 is considered high due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-15168?
To fix CVE-2025-15168, sanitize and validate all input parameters used in the /statistical.php file to prevent SQL injection.
What systems are affected by CVE-2025-15168?
CVE-2025-15168 affects the itsourcecode Student Management System version 1.0.
Can CVE-2025-15168 be exploited remotely?
Yes, CVE-2025-15168 can be exploited remotely, allowing attackers to manipulate the ID argument.
Is there a public exploit available for CVE-2025-15168?
Yes, there is a publicly available exploit for CVE-2025-15168 that demonstrates the SQL injection vulnerability.