CVE-2025-11614: SourceCodester Best Salon Management System edit-appointment.php sql injection
A vulnerability was identified in SourceCodester Best Salon Management System 1.0. Affected by this issue is some unknown functionality of the file /panel/edit-appointment.php. Such manipulation of the argument editid leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11614?
The severity of CVE-2025-11614 is critical due to its potential to allow remote SQL injection attacks.
How do I fix CVE-2025-11614?
To fix CVE-2025-11614, validate and sanitize user inputs in the /panel/edit-appointment.php file to prevent SQL injection.
Which systems are affected by CVE-2025-11614?
CVE-2025-11614 affects SourceCodester Best Salon Management System version 1.0.
What type of vulnerability is CVE-2025-11614?
CVE-2025-11614 is classified as an SQL injection vulnerability.
Can CVE-2025-11614 be exploited remotely?
Yes, CVE-2025-11614 can be exploited remotely, making it particularly dangerous.