A vulnerability has been found in SourceCodester Student Grades Management System 1.0. This issue affects some unknown processing of the file /grades.php of the component Add New Grade Page. The manipulation of the argument Remarks leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
History

Thu, 20 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Remyandrade
Remyandrade student Grades Management System
CPEs cpe:2.3:a:remyandrade:student_grades_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Remyandrade
Remyandrade student Grades Management System

Thu, 20 Nov 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester student Grades Management System
Vendors & Products Sourcecodester
Sourcecodester student Grades Management System

Tue, 18 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Nov 2025 14:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in SourceCodester Student Grades Management System 1.0. This issue affects some unknown processing of the file /grades.php of the component Add New Grade Page. The manipulation of the argument Remarks leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Title SourceCodester Student Grades Management System Add New Grade grades.php cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-11-18T14:02:06.819Z

Updated: 2025-11-18T14:20:14.687Z

Reserved: 2025-11-18T09:01:18.959Z

Link: CVE-2025-13349

cve-icon Vulnrichment

Updated: 2025-11-18T14:16:02.673Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-18T15:16:29.883

Modified: 2025-11-20T15:50:39.980

Link: CVE-2025-13349

cve-icon Redhat

No data.