CVE-2025-9595: code-projects Student Information Management System login.php cross site scripting
A vulnerability was found in code-projects Student Information Management System 1.0. The impacted element is an unknown function of the file /login.php. The manipulation of the argument uname results in cross site scripting. The attack may be performed from a remote location. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9595?
CVE-2025-9595 is classified as a cross-site scripting (XSS) vulnerability, which can have a moderate to high impact on affected systems.
How do I fix CVE-2025-9595?
To mitigate CVE-2025-9595, sanitize user input in the uname parameter to prevent injection of malicious scripts.
What are the consequences of CVE-2025-9595?
If exploited, CVE-2025-9595 can allow attackers to execute arbitrary scripts in the context of a user's session, leading to potential data theft or session hijacking.
Which software is affected by CVE-2025-9595?
CVE-2025-9595 affects the code-projects Student Information Management System version 1.0.
Can CVE-2025-9595 be exploited remotely?
Yes, CVE-2025-9595 can be exploited remotely, making it critical for users of the affected system to address the vulnerability promptly.