A security flaw has been discovered in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The impacted element is an unknown function of the file /Profilers/SProfile/reg.php. Performing manipulation of the argument USN results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.
Metrics
Affected Vendors & Products
References
History
Fri, 12 Dec 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The impacted element is an unknown function of the file /Profilers/SProfile/reg.php. Performing manipulation of the argument USN results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited. | |
| Title | kidaze CourseSelectionSystem reg.php sql injection | |
| Weaknesses | CWE-74 CWE-89 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-12-12T15:32:08.420Z
Updated: 2025-12-12T15:32:08.420Z
Reserved: 2025-12-12T11:07:56.964Z
Link: CVE-2025-14566
No data.
Status : Received
Published: 2025-12-12T16:15:42.943
Modified: 2025-12-12T16:15:42.943
Link: CVE-2025-14566
No data.