github.comrelatedexploit
https://github.com/0xEricTee/CVE/blob/main/Research/Stored_XSS.md CVE-2025-5727
MEDIUM
SourceCodester Student Result Management System Announcement Page announcement cross site scripting
Record summary
CVE-2025-5727 has a selected CVSS score of 4.8 (medium).
Description
A vulnerability classified as problematic has been found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /script/academic/announcement of the component Announcement Page. The manipulation of the argument Title leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 6, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Student Result Management SystemBrowse SourceCodester / Student Result Management System | CVE List | 1.0 | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-5727 VDB-311247 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.311247 VDB-311247 | SourceCodester Student Result Management System Announcement Page announcement cross site scriptingvdb entryTechnical description
https://vuldb.com/?id.311247 sourcecodester.comproduct
https://www.sourcecodester.com/