CVE-2025-11478: SourceCodester Farm Management System myCart.php sql injection
A weakness has been identified in SourceCodester Farm Management System 1.0. This issue affects some unknown processing of the file /myCart.php. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11478?
CVE-2025-11478 is classified as a high-severity vulnerability due to the potential for remote SQL injection attacks.
How do I fix CVE-2025-11478?
To fix CVE-2025-11478, sanitize and validate user inputs, specifically for the 'pid' parameter in the /myCart.php file.
What is the impact of CVE-2025-11478?
The impact of CVE-2025-11478 allows attackers to execute arbitrary SQL queries, potentially compromising the database.
In which system does CVE-2025-11478 exist?
CVE-2025-11478 exists in the SourceCodester Farm Management System version 1.0.
Who can exploit CVE-2025-11478?
CVE-2025-11478 can be exploited remotely by attackers targeting the vulnerable system.