CVE-2025-11615: SourceCodester Best Salon Management System add_invoice.php sql injection
A security flaw has been discovered in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/addinvoice.php. Performing manipulation of the argument ServiceId results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11615?
CVE-2025-11615 is considered a critical vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-11615?
To fix CVE-2025-11615, update the SourceCodester Best Salon Management System to a patched version that mitigates the SQL injection issue.
What component is affected by CVE-2025-11615?
CVE-2025-11615 affects the /panel/add_invoice.php file of the SourceCodester Best Salon Management System 1.0.
Can CVE-2025-11615 be exploited remotely?
Yes, CVE-2025-11615 can be exploited remotely, allowing attackers to manipulate ServiceId for SQL injection.
Who is impacted by CVE-2025-11615?
Users of SourceCodester Best Salon Management System version 1.0 are directly impacted by CVE-2025-11615.