CVE-2025-14565: Kidaze Courseselectionsystem

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affected element is an unknown function of the file /Profilers/SProfile/login1.php. Such manipulation of the argument Username leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.

Affected products

  • Kidaze Courseselectionsystem: up to and including 2017-06-18

Published 2025-12-12. Last modified 2026-10-07.