Cross Site Scripting Vulnerability in SourceCodester Online Student Clearance System
CVE-2025-4469
Key Information:
- Vendor
- Sourcecodester
- Vendor
- CVE Published:
- 9 May 2025
Badges
Summary
A cross site scripting vulnerability exists in the SourceCodester Online Student Clearance System 1.0, specifically within the 'add-admin.php' file. The vulnerability arises from improper handling of the 'Username' argument, allowing attackers to inject malicious scripts. This can be exploited remotely, potentially compromising user data and leading to unauthorized actions within the system. Notably, the details of this vulnerability have been publicly disclosed, raising concerns for users and administrators of the affected product.
Affected Version(s)
Online Student Clearance System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved