6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was found in itsourcecode Student Management System 1.0. Affected by this issue is some unknown functionality of the file /promote.php. The manipulation of the argument sy results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Basic Information
ID
CVE-2025-14336
Source
VulDB
Published
Dec 9, 2025 at 19:02
Affected Product
Vendor
itsourcecode
Product
Student Management System
Version
1.0
Affected Versions
itsourcecode Student Management System 1.0