CVE-2025-11611: SourceCodester Simple Inventory System user.php sql injection
A weakness has been identified in SourceCodester Simple Inventory System 1.0. Impacted is an unknown function of the file /user.php. This manipulation of the argument uemail causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11611?
CVE-2025-11611 is classified as a critical vulnerability due to its potential for remote SQL injection.
How do I fix CVE-2025-11611?
To fix CVE-2025-11611, sanitize user inputs and implement prepared statements in your SQL queries.
What is the impact of exploiting CVE-2025-11611?
Exploiting CVE-2025-11611 can lead to unauthorized access to the database and manipulation of sensitive data.
Is CVE-2025-11611 easy to exploit?
Yes, CVE-2025-11611 is considerd easy to exploit, as it can be carried out remotely with minimal technical knowledge.
Which version of SourceCodester Simple Inventory System is affected by CVE-2025-11611?
CVE-2025-11611 affects version 1.0 of SourceCodester Simple Inventory System.