A vulnerability categorized as critical has been discovered in SourceCodester Student Grading System 1.0. This affects an unknown part of the file /rms.php?page=users. Executing manipulation of the argument fname can lead to sql injection.
This vulnerability is tracked as CVE-2025-10409. The attack can be launched remotely. Moreover, an exploit is present.