CVE-2025-11662: SourceCodester Best Salon Management System booking.php sql injection
A security flaw has been discovered in SourceCodester Best Salon Management System 1.0. Impacted is an unknown function of the file /booking.php. The manipulation of the argument servid results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11662?
CVE-2025-11662 is classified as a high severity vulnerability due to the potential for remote SQL injection attacks.
How do I fix CVE-2025-11662?
To fix CVE-2025-11662, validate and sanitize user inputs for the 'serv_id' parameter in the /booking.php file to prevent SQL injection.
What software is affected by CVE-2025-11662?
CVE-2025-11662 affects the SourceCodester Best Salon Management System version 1.0.
What is the impact of CVE-2025-11662?
The impact of CVE-2025-11662 allows an attacker to manipulate the 'serv_id' argument and execute unauthorized SQL commands.
Can CVE-2025-11662 be exploited remotely?
Yes, CVE-2025-11662 can be exploited remotely, allowing attackers to target vulnerable installations from anywhere.