CVE-2025-10599 | itsourcecode Web-Based Internet Laboratory Management System 1.0 login.php User::AuthenticateUser user_email sql injection
A vulnerability marked as critical has been reported in itsourcecode Web-Based Internet Laboratory Management System 1.0. Impacted is the function User::AuthenticateUser of the file login.php. Performing manipulation of the argument user_email results in sql injection.
This vulnerability is known as CVE-2025-10599. Remote exploitation of the attack is possible. Furthermore, an exploit is available.