
🚨 HIGH: CVE-2025-14644 (CVSS 7.3) - SQL Injection in itsourcecode Student Management System 1.0 via /update_subject[.]php. Remotely exploitable, public exploit available. Patch immediately. #CVE #PatchNow https://t.co/zMqhwRvtvi
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
A vulnerability was determined in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /update_subject.php. Executing manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
NONE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.
1 version affected across 1 product

🚨 HIGH: CVE-2025-14644 (CVSS 7.3) - SQL Injection in itsourcecode Student Management System 1.0 via /update_subject[.]php. Remotely exploitable, public exploit available. Patch immediately. #CVE #PatchNow https://t.co/zMqhwRvtvi
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | angeljudesuarez | student_management_system | 1.0 | - | - |