CVE-2025-5727: SourceCodester Student Result Management System Announcement Page announcement cross site scripting
A vulnerability classified as problematic has been found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /script/academic/announcement of the component Announcement Page. The manipulation of the argument Title leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5727?
CVE-2025-5727 is classified as a problematic vulnerability affecting the SourceCodester Student Result Management System.
How do I fix CVE-2025-5727?
To mitigate CVE-2025-5727, ensure proper input sanitization on user-controlled fields in the Announcement Page component.
What type of attack does CVE-2025-5727 enable?
CVE-2025-5727 enables cross-site scripting (XSS) attacks through unvalidated user input in the Title argument.
Which component is affected by CVE-2025-5727?
CVE-2025-5727 affects the Announcement Page component within the SourceCodester Student Result Management System.
What impact could CVE-2025-5727 have on users?
CVE-2025-5727 could allow attackers to execute malicious scripts in the context of users' browsers, potentially leading to data theft or session hijacking.