Security Advisory

CVE-2025-11485

2.4
LOW

Vulnerability Description

A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function add_user of the file /admin.php of the component Manage Users Page. This manipulation of the argument first_name/last_name causes cross site scripting. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Published Date October 8, 2025
Official Source NIST NVD Advisory