
XSS vulnerability in SourceCodester Student Grades Management System (CVE-2025-63892)
Welcome to the official repository of my published CVE disclosures.
This repository contains detailed security advisories, proof-of-concept information, mitigation strategies, and technical analysis for vulnerabilities I have discovered.
📄 Advisory: CVE-2025-63892.md A stored XSS vulnerability in the classroom description field allows arbitrary JavaScript execution, session hijacking, and user impersonation.
📄 Advisory: CVE-2025-63883.md
Unsafe DOM manipulation in the search functionality permits attacker-controlled JavaScript execution via malicious URLs.
📄 Advisory: CVE-2025-9753.md
Improper input handling in the search box results in reflected XSS, enabling session theft and arbitrary JS execution.
Minhajul Taivin
Offensive Security Researcher · Red Team Bangladesh
🔗 https://www.linkedin.com/in/minhajultaivin
Specializing in vulnerability research, offensive security, and secure code analysis.
This repository showcases responsible disclosure efforts and assigned CVEs from MITRE.
For vendor communications, responsible disclosure, or collaboration:
All CVEs listed here have been reported responsibly and assigned by MITRE.
Proof-of-concepts are shared only for educational and defensive purposes.
Use of this information for malicious activity is strictly prohibited.