Junglewise Threat Intelligence

CVE-2025-67407: Sourcecodester CASAP Automated Enrollment System SQL injection in update_student.php

CVE-2025-67407 · Severity: info · CVSS 7.5 · Published 2026-07-29

Technologies: SourceCodester CASAP Automated Enrollment System. Vendors: SourceCodester.

Executive brief

Sourcecodester CASAP Automated Enrollment System, a software used for managing student registrations, contains a security flaw that allows unauthorized individuals to manipulate database queries. By sending specially crafted requests to the student update page, an attacker could potentially access sensitive information stored in the system's database. This could lead to the exposure of student records and other private administrative data.

Technical details

A SQL injection vulnerability exists in Sourcecodester CASAP Automated Enrollment System 1.0 within the 'update_student.php' component. The application fails to properly sanitize user-supplied input provided through the 'fname' and 'student_class' parameters before using them in a database query. A remote attacker can exploit this by sending malicious SQL commands to the server, potentially allowing for unauthorized data retrieval from the underlying database. The vulnerability is reachable over the network without requiring specific authentication, depending on the deployment configuration of the enrollment system.

Affected products

  • Sourcecodester CASAP Automated Enrollment System 1.0

Timeline

  • 2026-07-29: disclosed: Initial publication of CVE-2025-67407

References

Related threats