CVE-2025-57205 Details
Description
iNiLabs School Express (SMS Express) 6.2 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the content-management features available to authenticated admin users. The vulnerability resides in POSTed editor parameters submitted to the /posts/edit/{id} endpoint (and similarly in Notice and Pages editors). Due to insufficient input sanitization and output encoding, attackers can inject HTML/JS payloads. The payload is saved and later rendered unsanitized, resulting in JavaScript execution in other users' browsers when they access the affected content. This issue allows an authenticated attacker to execute arbitrary JavaScript in the context of another user, potentially leading to session hijacking, privilege escalation, data exfiltration, or administrative account takeover. The application does not enforce a restrictive Content Security Policy (CSP) or adequate filtering to prevent such attacks.
A stored cross-site scripting vulnerability has been identified in iNiLabs School Express (SMS Express) version 6.2. This vulnerability allows authenticated admin users to inject HTML and JavaScript payloads into the content management features. The injected payloads are saved and later executed in the browsers of other users, potentially leading to session hijacking, privilege escalation, data exfiltration, or administrative account takeover. The issue arises from inadequate input sanitization and output encoding, as well as the absence of a strict Content Security Policy (CSP) to mitigate such attacks.
Users are advised to upgrade to the latest version of iNiLabs School Express once a patch is available. In the meantime, monitor for suspicious HTML or JavaScript payloads in the database and restrict the use of input fields that allow for the injection of such content.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://grumpz.net/cve-2025-57205-stored-xss-in-inilabs-school-express-62-sms-express | CISA-ADP | ExploitThird Party Advisory |
| https://codecanyon.net/item/inilabs-school-management-system-express/11630340 | [email protected] | Product |
| https://grumpz.net/cve-2025-57205-stored-xss-in-inilabs-school-express-62-sms-express | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| inilabs school express | 6.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 3, 2025 | Initial Analysis | [email protected] |
| Sep 24, 2025 | CVE Modified | CISA-ADP |
| Sep 22, 2025 | New CVE Received | [email protected] |