CVE-2025-15052: Fabian Student Information System

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability was detected in code-projects Student Information System 1.0. This vulnerability affects unknown code of the file /profile.php. Performing manipulation of the argument firstname/lastname results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.

Affected products

  • Fabian Student Information System: version 1.0 only

Published 2025-12-24. Last modified 2026-06-17.