First published: Wed Feb 12 2025(Updated: )
A vulnerability was found in SourceCodester Best Church Management Software 1.1. It has been classified as critical. This affects an unknown part of the file /admin/app/role_crud.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
SourceCodester Best Church Management Software | ||
Church Management System | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1199 has been classified as a critical severity vulnerability.
CVE-2025-1199 allows for SQL injection through the manipulation of the 'id' argument in /admin/app/role_crud.php.
Exploiting CVE-2025-1199 could enable an attacker to execute arbitrary SQL commands on the database.
To mitigate CVE-2025-1199, input validation and prepared statements should be implemented to secure SQL queries.
CVE-2025-1199 affects SourceCodester Best Church Management Software version 1.1.