CVE-2025-9306 | SourceCodester Advanced School Management System 1.0 addNotice noticeSubject cross site scripting (EUVD-2025-25458)
A vulnerability, which was classified as problematic, was found in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown function of the file /index.php/notice/addNotice. The manipulation of the argument noticeSubject results in cross site scripting.
This vulnerability is known as CVE-2025-9306. It is possible to launch the attack remotely. Furthermore, an exploit is available.