Cross-Site Scripting Vulnerability in School Fees Payment System by Code-Projects
CVE-2025-6569
Key Information:
- Vendor
Code-projects
- Vendor
- CVE Published:
- 24 June 2025
Badges
What is CVE-2025-6569?
A vulnerability has been identified in the School Fees Payment System developed by Code-Projects, specifically within the /student.php file. This security issue allows attackers to perform cross-site scripting by manipulating the input parameters such as sname, contact, emailid, and transcation_remark. The exploiting of this vulnerability can be conducted remotely, potentially leading to unauthorized actions within a user's browser. This exploit has been disclosed publicly, raising serious concerns about the security integrity of the application and prompting immediate attention from users.
Affected Version(s)
School Fees Payment System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved