A flaw has been found in SourceCodester Online Student Clearance System 1.0. Impacted is an unknown function of the file /Admin/changepassword.php. This manipulation of the argument txtconfirm_password causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
2025-11-24T07:16:04.990
2025-12-02T03:09:12.143
Analyzed
CVSSv3.1: 4.7 (MEDIUM)
AV:N/AC:L/Au:M/C:P/I:P/A:P
6.4
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | senior-walter | online_student_clearance_system | 1.0 | Yes |