CVE-2025-5649

A vulnerability classified as critical has been found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /admin/core/new_user of the component Register Interface. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Configurations

Configuration 1 (hide)

cpe:2.3:a:razormist:student_result_management_system:1.0:*:*:*:*:*:*:*

History

10 Jun 2025, 15:05

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Razormist student Result Management System
Razormist
CPE cpe:2.3:a:razormist:student_result_management_system:1.0:*:*:*:*:*:*:*
References () https://github.com/Watskip/GeneralResearch/blob/main/Exploits/SRMS/Unauthorized%20privileged%20user%20creation.md - () https://github.com/Watskip/GeneralResearch/blob/main/Exploits/SRMS/Unauthorized%20privileged%20user%20creation.md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.311139 - () https://vuldb.com/?ctiid.311139 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.311139 - () https://vuldb.com/?id.311139 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.589458 - () https://vuldb.com/?submit.589458 - Third Party Advisory, VDB Entry
References () https://www.sourcecodester.com/ - () https://www.sourcecodester.com/ - Product
Summary
  • (es) Se ha detectado una vulnerabilidad crítica en SourceCodester Student Result Management System 1.0. Esta afecta a una parte desconocida del archivo /admin/core/new_user del componente Register Interface. La manipulación genera controles de acceso inadecuados. Es posible iniciar el ataque de forma remota. Se ha hecho público el exploit y puede que sea utilizado.

05 Jun 2025, 14:15

Type Values Removed Values Added
References () https://github.com/Watskip/GeneralResearch/blob/main/Exploits/SRMS/Unauthorized%20privileged%20user%20creation.md - () https://github.com/Watskip/GeneralResearch/blob/main/Exploits/SRMS/Unauthorized%20privileged%20user%20creation.md -

05 Jun 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-05 09:15

Updated : 2025-06-10 15:05


NVD link : CVE-2025-5649

Mitre link : CVE-2025-5649

CVE.ORG link : CVE-2025-5649


JSON object : View

Products Affected

razormist

  • student_result_management_system
CWE
CWE-266

Incorrect Privilege Assignment

CWE-284

Improper Access Control

NVD-CWE-noinfo