A security flaw has been discovered in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The impacted element is an unknown function of the file /Profilers/SProfile/reg.php. Performing manipulation of the argument USN results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.
Metrics
Affected Vendors & Products
References
History
Sun, 14 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kidaze
Kidaze courseselectionsystem |
|
| Vendors & Products |
Kidaze
Kidaze courseselectionsystem |
Fri, 12 Dec 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The impacted element is an unknown function of the file /Profilers/SProfile/reg.php. Performing manipulation of the argument USN results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited. | |
| Title | kidaze CourseSelectionSystem reg.php sql injection | |
| Weaknesses | CWE-74 CWE-89 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-12-12T15:32:08.420Z
Updated: 2025-12-12T15:32:08.420Z
Reserved: 2025-12-12T11:07:56.964Z
Link: CVE-2025-14566
No data.
Status : Awaiting Analysis
Published: 2025-12-12T16:15:42.943
Modified: 2025-12-15T18:22:40.637
Link: CVE-2025-14566
No data.