SQL Injection Vulnerability in SourceCodester Online Exam Form Submission by SourceCodester
CVE-2025-10625
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 17 September 2025
Badges
What is CVE-2025-10625?
An SQL injection vulnerability has been identified in the SourceCodester Online Exam Form Submission version 1.0, affecting the /user/dashboard.php?page=update_profile file. By manipulating the 'phone' argument, an attacker could potentially execute unauthorized SQL commands, leading to unauthorized access to user data. This exploit can be executed remotely, making it particularly concerning as other parameters may also be susceptible to injection attacks. Immediate remediation is recommended to protect sensitive data from malicious actors.
Affected Version(s)
Online Exam Form Submission 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
