CVE-2025-9306: SourceCodester Advanced School Management System addNotice cross site scripting
A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown function of the file /index.php/notice/addNotice. The manipulation of the argument noticeSubject results in cross site scripting. It is possible to launch the attack remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9306?
CVE-2025-9306 has been labeled with a high severity due to the potential for cross-site scripting attacks.
How do I fix CVE-2025-9306?
To fix CVE-2025-9306, implement proper input validation and sanitization for the noticeSubject parameter in the /index.php/notice/addNotice function.
What systems are affected by CVE-2025-9306?
CVE-2025-9306 affects SourceCodester Advanced School Management System version 1.0.
What type of attack can CVE-2025-9306 facilitate?
CVE-2025-9306 can facilitate cross-site scripting (XSS) attacks, allowing an attacker to inject malicious scripts.
Is authentication required to exploit CVE-2025-9306?
No, CVE-2025-9306 can potentially be exploited without authentication, making it a higher risk.