Junglewise Threat Intelligence

CVE-2025-60305: SourceCodester Online Student Clearance System incorrect access control

CVE-2025-60305 · Severity: high · CVSS 8.8 · Published 2025-10-10

Vendors: SourceCodester.

Executive brief

The Online Student Clearance System, a web application used to manage student graduation or departure clearances, contains a security flaw in its access control logic. This vulnerability allows a regular user, such as a student, to bypass security restrictions and perform administrative actions. An attacker could use this to modify records, approve their own clearances, or access sensitive student data, potentially disrupting school operations and compromising data integrity.

Technical details

An incorrect access control vulnerability (CWE-284) exists in SourceCodester Online Student Clearance System 1.0 due to a logic flaw in session validation. The application fails to properly verify the authorization level of a user when processing sensitive requests, such as adding user information or modifying database records. A remote attacker with low-level authenticated access can exploit this by capturing an administrative request and replacing the session identifiers (cookies) with their own. This allows the attacker to successfully execute high-privileged operations without possessing administrative credentials. A proof-of-concept demonstrates that administrative endpoints can be reached and manipulated by standard user accounts.

Affected products

  • SourceCodester Online Student Clearance System 1.0

Timeline

  • 2025-10-10: disclosed
  • 2025-10-10: advisory

References