github.comrelatedexploit
https://github.com/0xEricTee/CVE/blob/main/Research/Stored_XSS.md CVE-2025-5721
MEDIUM
SourceCodester Student Result Management System Profile Setting Page update_profile cross site scripting
Record summary
CVE-2025-5721 has a selected CVSS score of 4.8 (medium).
Description
A vulnerability, which was classified as problematic, was found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /script/academic/core/update_profile of the component Profile Setting Page. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 9, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Student Result Management SystemBrowse SourceCodester / Student Result Management System | CVE List | 1.0 | affected |
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-5721 VDB-311241 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.311241 VDB-311241 | SourceCodester Student Result Management System Profile Setting Page update_profile cross site scriptingvdb entry
https://vuldb.com/?id.311241 Submit #590569 | SourceCodester Student Result Management System 1.0 Cross Site ScriptingThird-party advisory
https://vuldb.com/?submit.590569 sourcecodester.comproduct
https://www.sourcecodester.com/