Improper Authorization in SourceCodester Online Student Clearance System
CVE-2025-14206
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 8 December 2025
Badges
What is CVE-2025-14206?
A vulnerability has been identified in SourceCodester's Online Student Clearance System version 1.0, specifically in the /Admin/delete-fee.php file related to the Fee Table Handler component. This issue arises from the manipulation of the argument ID, which can lead to improper authorization, allowing remote attackers to exploit the system. This vulnerability poses a risk due to its potential for unauthorized access and data manipulation, thus highlighting the importance of secure authentication measures.
Affected Version(s)
Online Student Clearance System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
