SQL Injection Vulnerability in SourceCodester Online Student Clearance System
CVE-2025-4331
Key Information:
- Vendor
- Sourcecodester
- Vendor
- CVE Published:
- 6 May 2025
Badges
Summary
A security flaw in the SourceCodester Online Student Clearance System 1.0 allows unauthorized users to exploit the /Admin/login.php file. By manipulating the username and password inputs, attackers can perform SQL injection attacks, enabling them to access sensitive information or perform unauthorized actions. This vulnerability can be triggered remotely, making it a serious concern for users of this software. It is imperative for system administrators to mitigate this risk by applying relevant security patches and best practices.
Affected Version(s)
Online Student Clearance System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved