{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amunywekistudent_result_management_system1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:munyweki:student_result_management_system:1.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":5.4,"id":"CVE-2025-4720"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Student Result Management System (1.0)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["SourceCodester"],"content_html":"\u003cp\u003eThe Munyweki Student Result Management System (SRMS) version 1.0 is susceptible to a path traversal vulnerability identified as CVE-2025-4720. The vulnerability exists within the \u003ccode\u003eacademic/core/drop_student.php\u003c/code\u003e script, which processes user-controlled input from the \u003ccode\u003eimg\u003c/code\u003e GET parameter. The application fails to sanitize this input before passing it to the PHP \u003ccode\u003eunlink()\u003c/code\u003e function. Consequently, an authenticated attacker can traverse the file system by providing directory traversal sequences (e.g., ../) in the parameter, leading to the unauthorized deletion of arbitrary files located on the server. The lack of validation on the \u003ccode\u003eimg\u003c/code\u003e input makes the system highly vulnerable to destructive actions if an attacker gains authenticated access.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify the presence of the SRMS 1.0 application.\u003c/li\u003e\n\u003cli\u003eAttacker obtains valid credentials to authenticate to the SRMS platform.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the \u003ccode\u003eacademic/core/drop_student.php\u003c/code\u003e administrative function.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious GET request containing a path traversal payload in the \u003ccode\u003eimg\u003c/code\u003e parameter (e.g., \u003ccode\u003e?img=../../../../config.php\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe server-side script receives the payload and directly passes the unsanitized string to the \u003ccode\u003eunlink()\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eunlink()\u003c/code\u003e function executes the deletion against the resolved file path on the web server.\u003c/li\u003e\n\u003cli\u003eTargeted system files are deleted, potentially causing denial of service or configuration loss.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2025-4720 allows an authenticated attacker to delete arbitrary files on the underlying web server. This could result in the destruction of critical application configuration files, database backups, or core system files, leading to a complete denial of service of the Student Result Management System.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and remediation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to monitor for suspicious path traversal patterns in web server logs targeting \u003ccode\u003edrop_student.php\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for any requests to \u003ccode\u003edrop_student.php\u003c/code\u003e containing \u003ccode\u003e../\u003c/code\u003e sequences in the \u003ccode\u003eimg\u003c/code\u003e query parameter.\u003c/li\u003e\n\u003cli\u003eAudit the file system permissions of the web application directory to ensure the web server service account has the minimum necessary privileges to prevent unauthorized file deletion.\u003c/li\u003e\n\u003cli\u003ePatch or disable the vulnerable \u003ccode\u003eacademic/core/drop_student.php\u003c/code\u003e component if it is not strictly required for business operations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T20:27:12Z","date_published":"2026-08-26T20:27:12Z","id":"https://feed.craftedsignal.io/briefs/2026-08-srms-path-traversal/","summary":"SourceCodester Student Result Management System 1.0 contains a path traversal vulnerability (CVE-2025-4720) in the drop_student.php endpoint, allowing authenticated attackers to perform arbitrary file deletion via the 'img' parameter.","title":"Path Traversal Vulnerability in SourceCodester SRMS","url":"https://feed.craftedsignal.io/briefs/2026-08-srms-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:munyweki:student_result_management_system:1.0:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}