Vulnerability Description
A vulnerability was detected in SourceCodester Online Exam Form Submission 1.0. Affected by this vulnerability is an unknown functionality of the file /user/dashboard.php?page=update_profile. The manipulation of the argument phone results in sql injection. The attack may be launched remotely. The exploit is now public and may be used. Other parameters might be affected as well.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Janobe | Online Exam Form Submission | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/qcycop0101-hash/CVE/issues/24ExploitIssue TrackingThird Party Advisory
- https://vuldb.com/?ctiid.324655Permissions RequiredVDB Entry
- https://vuldb.com/?id.324655Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.650444Third Party AdvisoryVDB Entry
- https://www.sourcecodester.com/Product
- https://github.com/qcycop0101-hash/CVE/issues/24ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2025-10625?
CVE-2025-10625 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability was detected in SourceCodester Online Exam Form Submission 1.0. Affected by this vulnerability is an unknown functionality of the file /user/dashboard.php?page=update_profile. The mani...
How severe is CVE-2025-10625?
CVE-2025-10625 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-10625?
Check the references section above for vendor advisories and patch information. Affected products include: Janobe Online Exam Form Submission.