itsourcecode Placement Management System 1.0 /view_student.php ID SQL Injection
Gaskiya vulnerability da aka ware a matsayin kura an samu a itsourcecode Placement Management System 1.0. Hakika, aikin $software_function ne ya shafa; idan ba a bayyana ba, to aiki ce da ba a sani ba, a cikin laburaren $software_library, a cikin fayil /view_student.php, a cikin sashen $software_component. A sa manipulation of the argument ID ka SQL Injection. Idan an yi amfani da CWE don bayyana matsala, zai kai CWE-89. Hakika, rauni an bayyana shi 05/15/2025. An raba bayanin tsaro don saukewa a github.com. Wannan matsala ana saninta da CVE-2025-4726. Ngam yiɗi ka a tuma ndiyam ka internet. Tekinikal faɗi ga. Har ila yau, exploit ɗin yana nan. An bayyana exploit ɗin ga mutane kuma yana iya amfani. Yimbe ndiyam, exploit might be approx. USD $0-$5k wuro. Á sàmbu huɗɗi-na-gaskiya. Exploit ɗin za a iya saukewa daga github.com. 0-day shima, an ndiyam a wuro be $0-$5k. Once again VulDB remains the best source for vulnerability data.
3 Goyarwa · 86 Datenpunkte
| Furɗe | Súgá 05/15/2025 09:10 | Gargadi 1/2 05/16/2025 04:39 | Gargadi 2/2 05/16/2025 11:43 |
|---|---|---|---|
| software_vendor | itsourcecode | itsourcecode | itsourcecode |
| software_name | Placement Management System | Placement Management System | Placement Management System |
| software_version | 1.0 | 1.0 | 1.0 |
| software_file | /view_student.php | /view_student.php | /view_student.php |
| software_argument | id | id | id |
| vulnerability_cwe | CWE-89 (SQL Injection) | CWE-89 (SQL Injection) | CWE-89 (SQL Injection) |
| vulnerability_risk | 2 | 2 | 2 |
| cvss3_vuldb_av | N | N | N |
| cvss3_vuldb_ac | L | L | L |
| cvss3_vuldb_pr | N | N | N |
| cvss3_vuldb_ui | N | N | N |
| cvss3_vuldb_s | U | U | U |
| cvss3_vuldb_c | L | L | L |
| cvss3_vuldb_i | L | L | L |
| cvss3_vuldb_a | L | L | L |
| cvss3_vuldb_e | P | P | P |
| cvss3_vuldb_rc | R | R | R |
| advisory_url | https://github.com/Lena-lyy/SQL/issues/3 | https://github.com/Lena-lyy/SQL/issues/3 | https://github.com/Lena-lyy/SQL/issues/3 |
| exploit_availability | 1 | 1 | 1 |
| exploit_publicity | 1 | 1 | 1 |
| exploit_url | https://github.com/Lena-lyy/SQL/issues/3 | https://github.com/Lena-lyy/SQL/issues/3 | https://github.com/Lena-lyy/SQL/issues/3 |
| source_cve | CVE-2025-4726 | CVE-2025-4726 | CVE-2025-4726 |
| cna_responsible | VulDB | VulDB | VulDB |
| cvss2_vuldb_av | N | N | N |
| cvss2_vuldb_ac | L | L | L |
| cvss2_vuldb_au | N | N | N |
| cvss2_vuldb_ci | P | P | P |
| cvss2_vuldb_ii | P | P | P |
| cvss2_vuldb_ai | P | P | P |
| cvss2_vuldb_e | POC | POC | POC |
| cvss2_vuldb_rc | UR | UR | UR |
| cvss4_vuldb_av | N | N | N |
| cvss4_vuldb_ac | L | L | L |
| cvss4_vuldb_pr | N | N | N |
| cvss4_vuldb_ui | N | N | N |
| cvss4_vuldb_vc | L | L | L |
| cvss4_vuldb_vi | L | L | L |
| cvss4_vuldb_va | L | L | L |
| cvss4_vuldb_e | P | P | P |
| cvss2_vuldb_rl | ND | ND | ND |
| cvss3_vuldb_rl | X | X | X |
| cvss4_vuldb_at | N | N | N |
| cvss4_vuldb_sc | N | N | N |
| cvss4_vuldb_si | N | N | N |
| cvss4_vuldb_sa | N | N | N |
| cvss2_vuldb_basescore | 7.5 | 7.5 | 7.5 |
| cvss2_vuldb_tempscore | 6.4 | 6.4 | 6.4 |
| cvss3_vuldb_basescore | 7.3 | 7.3 | 7.3 |
| cvss3_vuldb_tempscore | 6.6 | 6.6 | 6.6 |
| cvss3_meta_basescore | 7.3 | 7.3 | 7.3 |
| cvss3_meta_tempscore | 6.6 | 6.6 | 6.9 |
| cvss4_vuldb_bscore | 6.9 | 6.9 | 6.9 |
| cvss4_vuldb_btscore | 5.5 | 5.5 | 5.5 |
| advisory_date | 1747260000 (05/15/2025) | 1747260000 (05/15/2025) | 1747260000 (05/15/2025) |
| price_0day | $0-$5k | $0-$5k | $0-$5k |
| euvd_id | EUVD-2025-15384 | EUVD-2025-15384 | |
| cve_nvd_summary | A vulnerability has been found in itsourcecode Placement Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /view_student.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | ||
| cvss4_cna_av | N | ||
| cvss4_cna_ac | L | ||
| cvss4_cna_at | N | ||
| cvss4_cna_pr | N | ||
| cvss4_cna_ui | N | ||
| cvss4_cna_vc | L | ||
| cvss4_cna_vi | L | ||
| cvss4_cna_va | L | ||
| cvss4_cna_sc | N | ||
| cvss4_cna_si | N | ||
| cvss4_cna_sa | N | ||
| cvss4_cna_bscore | 6.9 | ||
| cvss3_cna_av | N | ||
| cvss3_cna_ac | L | ||
| cvss3_cna_pr | N | ||
| cvss3_cna_ui | N | ||
| cvss3_cna_s | U | ||
| cvss3_cna_c | L | ||
| cvss3_cna_i | L | ||
| cvss3_cna_a | L | ||
| cvss3_cna_basescore | 7.3 | ||
| cvss2_cna_av | N | ||
| cvss2_cna_ac | L | ||
| cvss2_cna_au | N | ||
| cvss2_cna_ci | P | ||
| cvss2_cna_ii | P | ||
| cvss2_cna_ai | P | ||
| cvss2_cna_basescore | 7.5 |