CVE-2025-5724: SourceCodester Student Result Management System Subjects Page subjects cross site scripting

4.8 CVSS

Description

A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /script/academic/subjects of the component Subjects Page. The manipulation of the argument Subject leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Es wurde eine problematische Schwachstelle in SourceCodester Student Result Management System 1.0 ausgemacht. Betroffen hiervon ist ein unbekannter Ablauf der Datei /script/academic/subjects der Komponente Subjects Page. Durch Beeinflussen des Arguments Subject mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Exploit steht zur öffentlichen Verfügung.

Classification

CVE ID: CVE-2025-5724

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.8

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

Problem Types

Cross Site Scripting Code Injection

Affected Products

Vendor: SourceCodester

Product: Student Result Management System

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.03% (probability of being exploited)

EPSS Percentile: 6.89% (scored less or equal to compared to others)

EPSS Date: 2025-06-06 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-5724
https://vuldb.com/?id.311244
https://vuldb.com/?ctiid.311244
https://github.com/0xEricTee/CVE/blob/main/Research/Stored_XSS.md
https://github.com/0xEricTee/CVE/blob/main/Research/Stored_XSS.md#field-4-subject-field-in-subjects-page
https://www.sourcecodester.com/

Timeline