CVE-2025-4898 | SourceCodester Student Result Management System 1.0 Logo File update_system.php unlink old_logo path traversal (EUVD-2025-15643)
A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as critical. This vulnerability affects the function unlink of the file update_system.php of the component Logo File Handler. The manipulation of the argument old_logo leads to path traversal.
This vulnerability was named CVE-2025-4898. The attack can be initiated remotely. Furthermore, there is an exploit available.