CVE-2025-12293: SourceCodester Point of Sales category.php sql injection
Published Oct 27, 2025
·Updated
A vulnerability was identified in SourceCodester Point of Sales 1.0. This issue affects some unknown processing of the file /category.php. Such manipulation of the argument Category leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Affected Software
2 affected components
Sourcecodester Point of Sales
Janobe Point Of Sales=1.0
Event History
Oct 27, 2025
CVE Published
via MITRE·04:02 PM
Data Sourced
via MITRE·04:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12293?
CVE-2025-12293 has a high severity due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2025-12293?
To fix CVE-2025-12293, you should sanitize and validate all user inputs, particularly those processed by /category.php.
3
What software is affected by CVE-2025-12293?
CVE-2025-12293 affects SourceCodester Point of Sales version 1.0.
4
Can CVE-2025-12293 be exploited remotely?
Yes, CVE-2025-12293 can be exploited remotely through the vulnerability in the /category.php file.
5
What type of vulnerability is CVE-2025-12293?
CVE-2025-12293 is classified as an SQL injection vulnerability.