SQL Injection Vulnerability in SourceCodester Student Grading System
CVE-2025-10418
Key Information:
- Vendor
Sourcecodester
- Status
- Vendor
- CVE Published:
- 15 September 2025
Badges
What is CVE-2025-10418?
A SQL injection vulnerability has been discovered in the SourceCodester Student Grading System version 1.0, specifically in the file /view_students.php. This issue arises from inadequate validation of the input parameters, allowing attackers to manipulate the ID argument and execute arbitrary SQL queries. This flaw can be leveraged remotely, posing a significant risk to database security. Publicly accessible exploit code has been released, heightening the urgency for users to implement appropriate security measures and updates.
Affected Version(s)
Student Grading System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved