SQL Injection Vulnerability in SourceCodester Advanced School Management System
CVE-2025-9689
5.3MEDIUM
What is CVE-2025-9689?
A SQL injection vulnerability exists in the SourceCodester Advanced School Management System 1.0, specifically in the /index.php/stock/item_select function. This security flaw can be exploited by manipulating the 'q' argument, allowing attackers to execute arbitrary SQL queries on the database. This vulnerability can be exploited remotely, and the details of this exploit are now publicly available.
Affected Version(s)
Advanced School Management System 1.0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
horime (VulDB User)