6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was identified in itsourcecode Student Management System 1.0. This vulnerability affects unknown code of the file /edit_user.php. The manipulation of the argument fname leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. Other parameters might be affected as well.
Basic Information
ID
CVE-2025-14226
Source
VulDB
Published
Dec 8, 2025 at 09:32
Affected Product
Vendor
itsourcecode
Product
Student Management System
Version
1.0
Affected Versions
itsourcecode Student Management System 1.0