CVE-2025-9306

LOW

SourceCodester Advanced School Management System 1.0 - XSS

Title source: llm
STIX 2.1

Description

A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown function of the file /index.php/notice/addNotice. The manipulation of the argument noticeSubject results in cross site scripting. It is possible to launch the attack remotely. The exploit is now public and may be used.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.320911
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.320911
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.632419
Exploit, Issue Tracking, Third Party Advisory issue-tracking
https://github.com/lrjbsyh/CVE_Hunter/issues/3
Exploit, Issue Tracking, Third Party Advisory exploit issue-tracking
https://github.com/lrjbsyh/CVE_Hunter/issues/3#issue-3313419319

Scores

CVSS v3 3.5
EPSS 0.0025
EPSS Percentile 16.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79 CWE-94
Status published
Products (1)
donbermoy/advanced_school_management_system 1.0
Published Aug 21, 2025
Tracked Since Feb 18, 2026