A vulnerability was found in SourceCodester Student Grading System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /view_user.php. Such manipulation of the argument ID leads to sql injection.

This vulnerability is referenced as CVE-2025-10407. It is possible to launch the attack remotely. Furthermore, an exploit is available.