SQL Injection Vulnerability in SourceCodester Online Student File Management System
CVE-2025-10593
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 17 September 2025
Badges
What is CVE-2025-10593?
A security flaw has been identified in the SourceCodester Online Student File Management System version 1.0, specifically within the file /admin/update_student.php. An attacker can exploit this vulnerability through the manipulation of the stud_id argument, resulting in SQL injection. This incident allows remote execution of potentially harmful commands that could compromise the database and the sensitive data it holds. Once disclosed, the exploit has been made public, amplifying the risk for unsuspecting users.
Affected Version(s)
Online Student File Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved