CVE-2025-4470
A vulnerability classified as problematic was found in SourceCodester Online Student Clearance System 1.0.
Does this matter?
Lower severity and a low EPSS score (0.60%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability classified as problematic was found in SourceCodester Online Student Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add-student.php. The manipulation of the argument Fullname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
- CVSS 4.0
- 4.8 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.60% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79, CWE-94
- Affected
- senior-walter/online student clearance system
- Source
- cna@vuldb.com
References
- https://github.com/Colorado-all/cve/blob/main/Online%20Student%20Clearance%20System/xss-2.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.308089Permissions Required, VDB Entry
- https://vuldb.com/?id.308089Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.566249Third Party Advisory, VDB Entry
- https://www.sourcecodester.com/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.