Skip to main content

CVE-2025-6475: Razormist Student Result Management XSS Flaw

CVE-2025-6475 is a cross-site scripting vulnerability in Razormist Student Result Management System affecting the Manage Students Module. Attackers can inject malicious scripts remotely. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2025-6475 Overview

CVE-2025-6475 is a cross-site scripting (XSS) vulnerability in SourceCodester Student Result Management System version 1.0, developed by razormist. The flaw resides in the /script/admin/manage_students endpoint of the Manage Students Module. An authenticated attacker can inject arbitrary JavaScript that executes in the browser context of users who view the affected page. The issue is tracked under CWE-79 and was publicly disclosed with proof-of-concept details.

Critical Impact

Authenticated attackers can inject persistent script payloads through the Manage Students interface, enabling session hijacking, credential theft, or administrative action forgery against users of the application.

Affected Products

  • SourceCodester Student Result Management System 1.0
  • razormist Student Result Management System (CPE: cpe:2.3:a:razormist:student_result_management_system:1.0)
  • Deployments exposing the Manage Students Module to authenticated users

Discovery Timeline

  • 2025-06-22 - CVE-2025-6475 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-6475

Vulnerability Analysis

The vulnerability is a stored or reflected cross-site scripting flaw in the Manage Students Module of the Student Result Management System. User-supplied input processed by /script/admin/manage_students is rendered back to the browser without sufficient output encoding or input sanitization. An attacker with access to the module can submit HTML or JavaScript payloads that execute when another user loads the page.

The EPSS probability for this issue is 0.297% as of 2026-10-06, reflecting limited observed exploitation attempts. However, a public proof-of-concept exists in the GitHub PoC Repository and the issue is catalogued in VulDB Vulnerability Report #313583.

Root Cause

The root cause is improper neutralization of user input during web page generation, classified as CWE-79. Server-side code accepts attacker-controlled parameters tied to student record fields and emits them into the HTML response without context-aware escaping. Standard output encoding routines or a template engine with auto-escaping would prevent the behavior.

Attack Vector

Exploitation requires network access to the application and authenticated privileges to interact with the Manage Students Module. The attacker submits a payload containing JavaScript through a vulnerable input field. When an administrator or another privileged user views the affected record, the payload executes in that user's browser session, potentially stealing session cookies, performing CSRF-like actions, or defacing the interface. Refer to the GitHub PoC Repository for the disclosed payload details.

Detection Methods for CVE-2025-6475

Indicators of Compromise

  • HTTP POST or GET requests to /script/admin/manage_students containing <script>, onerror=, onload=, or encoded JavaScript payloads
  • Unexpected outbound requests from administrator browsers to attacker-controlled domains shortly after visiting the Manage Students page
  • Student record fields in the database containing HTML tags or JavaScript event handlers

Detection Strategies

  • Review web server access logs for anomalous query strings or form parameters targeting /script/admin/manage_students
  • Deploy a Web Application Firewall rule set that flags common XSS payload patterns on the application's admin endpoints
  • Perform periodic database audits of student record fields for stored HTML or script content

Monitoring Recommendations

  • Enable browser Content Security Policy (CSP) reporting to capture inline script violations on administrative pages
  • Alert on session cookie exfiltration patterns, such as cookies being appended to outbound URL parameters
  • Monitor for new or modified administrator accounts following access to the Manage Students Module

How to Mitigate CVE-2025-6475

Immediate Actions Required

  • Restrict access to the /script/admin/manage_students endpoint to trusted administrator IP ranges until a patch is applied
  • Audit existing student records for stored script payloads and sanitize affected rows
  • Rotate administrator session tokens and credentials if exploitation is suspected

Patch Information

No vendor-supplied patch has been published by razormist or SourceCodester at the time of writing. Review the VulDB Vulnerability Report #313583 and the SourceCodester Security Resources page for any later advisories. Organizations relying on this application should evaluate alternative solutions or apply the workarounds below.

Workarounds

  • Implement a reverse proxy or WAF rule that strips or blocks requests containing HTML control characters to the vulnerable endpoint
  • Apply server-side output encoding to all fields rendered from the students table using context-aware escaping libraries
  • Enforce a strict Content Security Policy that disallows inline scripts (script-src 'self') across the administrative interface
  • Limit administrator accounts to the minimum required and require multi-factor authentication for all privileged logins
bash
# Example nginx configuration adding a restrictive CSP header
# for the Student Result Management System admin interface
location /script/admin/ {
    add_header Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; frame-ancestors 'none'" always;
    add_header X-Content-Type-Options "nosniff" always;
    add_header X-Frame-Options "DENY" always;
    allow 10.0.0.0/8;
    deny all;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.