CVE-2025-12932: SourceCodester Baby Care System admin.php sql injection
A vulnerability was determined in SourceCodester Baby Care System 1.0. Affected by this issue is some unknown functionality of the file /admin.php?id=inbox. This manipulation of the argument msgid causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12932?
CVE-2025-12932 has a high severity due to its potential to allow remote SQL injection attacks.
How do I fix CVE-2025-12932?
To fix CVE-2025-12932, ensure that input validation and parameterized queries are implemented in the application.
Which software is affected by CVE-2025-12932?
CVE-2025-12932 affects SourceCodester Baby Care System version 1.0.
How can CVE-2025-12932 be exploited?
CVE-2025-12932 can be exploited by manipulating the 'msgid' parameter in the /admin.php?id=inbox file.
What are the potential impacts of CVE-2025-12932?
The potential impacts of CVE-2025-12932 include unauthorized data access, data manipulation, and exposure of sensitive information.