CVE-2025-9838: itsourcecode Student Information Management System index.php sql injection
A vulnerability was identified in itsourcecode Student Information Management System 1.0. Impacted is an unknown function of the file /admin/modules/subject/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9838?
CVE-2025-9838 is classified as a high-severity vulnerability due to its potential for remote SQL injection.
How do I fix CVE-2025-9838?
To fix CVE-2025-9838, validate and sanitize user inputs in the affected function and apply parameterized queries.
What type of attack does CVE-2025-9838 facilitate?
CVE-2025-9838 facilitates SQL injection attacks that can be executed remotely.
Which software is affected by CVE-2025-9838?
CVE-2025-9838 affects the itsourcecode Student Information Management System version 1.0.
Is there a known exploit for CVE-2025-9838?
Yes, there is a known publicly available exploit for CVE-2025-9838 that demonstrates the SQL injection vulnerability.