Description
A vulnerability was detected in code-projects Student Information System 1.0. This vulnerability affects unknown code of the file /profile.php. Performing manipulation of the argument firstname/lastname results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Problem types
Product status
Timeline
| 2025-12-23: | Advisory disclosed |
| 2025-12-23: | VulDB entry created |
| 2025-12-23: | VulDB entry last update |
Credits
i4g5d (VulDB User)
References
vuldb.com/?id.337858 (VDB-337858 | code-projects Student Information System profile.php cross site scripting)
vuldb.com/?ctiid.337858 (VDB-337858 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.720765 (Submit #720765 | Fabian Ros Student Information System In PHP With Source Code November 2, 2025 Cross Site Scripting)
github.com/...TICAL-SECURITY-VULNERABILITY-REPORT-Stored-XSS
code-projects.org/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.