CVE-2025-0872: itsourcecode Tailoring Management System addpayment.php sql injection
A vulnerability classified as critical has been found in itsourcecode Tailoring Management System 1.0. Affected is an unknown function of the file /addpayment.php. The manipulation of the argument id/amount/desc/inccat leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0872?
CVE-2025-0872 has been classified as critical due to the potential for SQL injection attacks.
How do I fix CVE-2025-0872?
To mitigate CVE-2025-0872, ensure that all user inputs in the /addpayment.php file are properly sanitized and use prepared statements for database interactions.
What systems are affected by CVE-2025-0872?
CVE-2025-0872 affects itsourcecode Tailoring Management System 1.0.
Can CVE-2025-0872 be exploited remotely?
Yes, CVE-2025-0872 can be exploited remotely by manipulating the parameters sent to the /addpayment.php file.
What kind of attack can be executed due to CVE-2025-0872?
CVE-2025-0872 allows for SQL injection attacks which can compromise the security of the database.