github.comexploit
https://github.com/Watskip/GeneralResearch/blob/main/Exploits/SRMS/Unauthorized%20privileged%20user%20creation.md CVE-2025-5649
MEDIUM
SourceCodester Student Result Management System Register Interface new_user access control
Record summary
CVE-2025-5649 has a selected CVSS score of 6.9 (medium).
Description
A vulnerability classified as critical has been found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /admin/core/new_user of the component Register Interface. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 5, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Student Result Management SystemBrowse SourceCodester / Student Result Management System | CVE List | 1.0 | affected |
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-5649 VDB-311139 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.311139 VDB-311139 | SourceCodester Student Result Management System Register Interface new_user access controlvdb entry
https://vuldb.com/?id.311139 Submit #589458 | SourceCodester Student Result Management System 1.0 Improper Access Control for Register InterfaceThird-party advisory
https://vuldb.com/?submit.589458 sourcecodester.comproduct
https://www.sourcecodester.com/