Cross-Site Scripting Vulnerability in SourceCodester Online Courseware
CVE-2025-0800
5.1MEDIUM
What is CVE-2025-0800?
A vulnerability has been identified in SourceCodester Online Courseware 1.0, specifically in the Edit Teacher function found in the file /pcci/admin/saveeditt.php. This flaw arises from improper handling of the 'fname' argument, enabling attackers to execute malicious scripts in the context of another user's session. The vulnerability poses a significant risk as it can be exploited remotely, allowing unauthorized users to inject arbitrary JavaScript into web pages viewed by other users. The publicly disclosed nature of this exploit heightens the urgency for remediation.
Affected Version(s)
Online Courseware 1.0