A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0. Impacted is the function User::AuthenticateUser of the file login.php. Performing manipulation of the argument user_email results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.
References
| Link | Resource |
|---|---|
| https://github.com/drew-byte/Web-Based-Internet-Laboratory-Management-System_SQLi-PoC/blob/main/README.md | Exploit Third Party Advisory |
| https://itsourcecode.com/ | Product |
| https://vuldb.com/?ctiid.324616 | Permissions Required VDB Entry |
| https://vuldb.com/?id.324616 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.649501 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-09-17 16:15
Updated : 2025-09-22 15:02
NVD link : CVE-2025-10599
Mitre link : CVE-2025-10599
CVE.ORG link : CVE-2025-10599
JSON object : View
Products Affected
itsourcecode
- web-based_internet_laboratory_management_system
