PT-2025-45280 · Codexpert+1 · Coschool Lms+1

CVE-2025-60239

·

Published

2025-07-14

·

Updated

2025-11-06

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions CoSchool LMS versions prior to 1.4.4
Description An issue exists where the software fails to properly neutralize special elements used in SQL commands, allowing for Blind SQL Injection. This occurs due to insufficient escaping of user-supplied parameters and a lack of sufficient preparation of the SQL query. Authenticated attackers with subscriber-level access or higher can append additional SQL queries to existing ones to extract sensitive information from the database.
Recommendations Update CoSchool LMS to a version newer than 1.4.3.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-60239

Affected Products

Coschool Lms
Coschool