A vulnerability classified as critical has been found in SourceCodester Online Student Result System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. Performing manipulation of the argument Username results in sql injection.

This vulnerability is identified as CVE-2025-11601. The attack can be initiated remotely. Additionally, an exploit exists.