CVE-2025-12294: SourceCodester Point of Sales delete_category.php sql injection
A security flaw has been discovered in SourceCodester Point of Sales 1.0. Impacted is an unknown function of the file /deletecategory.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12294?
CVE-2025-12294 is rated as a high severity vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-12294?
To fix CVE-2025-12294, ensure that input validation and parameterized queries are implemented in the /delete_category.php file.
What systems are affected by CVE-2025-12294?
CVE-2025-12294 affects the SourceCodester Point of Sales version 1.0.
Can CVE-2025-12294 be exploited remotely?
Yes, CVE-2025-12294 can be exploited remotely by manipulating the ID parameter in the affected script.
What should I do if I am using SourceCodester Point of Sales 1.0?
If using SourceCodester Point of Sales 1.0, you should assess your system for instances of CVE-2025-12294 and apply appropriate mitigations immediately.