CVE-2025-11479: SourceCodester Wedding Reservation Management System function.php insertReservation sql injection
A security vulnerability has been detected in SourceCodester Wedding Reservation Management System 1.0. Impacted is the function insertReservation of the file function.php. Such manipulation of the argument number leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11479?
CVE-2025-11479 is classified as a high-severity SQL injection vulnerability.
How do I fix CVE-2025-11479?
To fix CVE-2025-11479, you should validate and sanitize all user inputs, especially the 'number' argument in the insertReservation function.
Can CVE-2025-11479 be exploited remotely?
Yes, CVE-2025-11479 can be exploited remotely, allowing attackers to manipulate the argument to perform SQL injection.
Which software is affected by CVE-2025-11479?
CVE-2025-11479 affects SourceCodester Wedding Reservation Management System version 1.0.
What kind of attack is possible with CVE-2025-11479?
CVE-2025-11479 enables attackers to execute SQL injection attacks, potentially compromising the database.