A vulnerability described as critical has been identified in itsourcecode Web-Based Internet Laboratory Management System 1.0. This impacts an unknown function of the file /user/controller.php. Executing manipulation can lead to sql injection.

This vulnerability appears as CVE-2025-13299. The attack may be performed from remote. In addition, an exploit is available.