CVE-2025-9839: itsourcecode Student Information Management System index.php sql injection
A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/course/index.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9839?
CVE-2025-9839 has a high severity rating due to the potential for SQL injection exploits.
How do I fix CVE-2025-9839?
To fix CVE-2025-9839, you should validate and sanitize input parameters in the affected file /admin/modules/course/index.php.
Who is affected by CVE-2025-9839?
CVE-2025-9839 affects users of the itsourcecode Student Information Management System version 1.0.
What kind of attack can be executed through CVE-2025-9839?
CVE-2025-9839 allows attackers to perform SQL injection attacks which may lead to unauthorized access to the database.
Is CVE-2025-9839 being actively exploited?
There is a possibility of active exploitation of CVE-2025-9839 given the nature of SQL injection vulnerabilities.