---
id: CVE-2025-10387
title: A vulnerability was determined in codesiddhant Jasmin Ransomware up to 1.0.1
summary: >-
  A vulnerability was determined in codesiddhant Jasmin Ransomware up to 1.0.1.
  This vulnerability affects unknown code of the file /handshake.php. This
  manipulation of the argument
  machine_name/computer_user/os/date/time/ip/location/syste…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
  - CWE-89
vendor: codesiddhant
product: jasmin_ransomware
affected:
  - jasmin_ransomware = 1.0.1
published: '2025-09-14'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10387'
references:
  - url: >-
      https://github.com/YZS17/CVE/blob/main/Jasmin-Ransomware/sqli_handshake.php.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.323822'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.323822'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.644285'
    label: cna@vuldb.com
  - url: >-
      https://github.com/YZS17/CVE/blob/main/Jasmin-Ransomware/sqli_handshake.php.md
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00414
epssPercentile: 0.33254
ingestedAt: '2026-09-30T23:29:32.383Z'
---

## Overview

A vulnerability was determined in codesiddhant Jasmin Ransomware up to 1.0.1. This vulnerability affects unknown code of the file /handshake.php. This manipulation of the argument machine_name/computer_user/os/date/time/ip/location/systemid/password causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `jasmin_ransomware = 1.0.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
