CVE-2025-12933: SourceCodester Baby Care System updatewelcome.php sql injection
A vulnerability was identified in SourceCodester Baby Care System 1.0. This affects an unknown part of the file /updatewelcome.php?id=siteoptions&action=welcome. Such manipulation of the argument roleid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12933?
CVE-2025-12933 is classified as a high-severity vulnerability due to its potential for remote SQL injection.
How do I fix CVE-2025-12933?
To fix CVE-2025-12933, sanitize and validate all user inputs, particularly the 'roleid' parameter in the /updatewelcome.php file.
What are the implications of exploiting CVE-2025-12933?
Exploitation of CVE-2025-12933 can lead to unauthorized database access and manipulation, compromising the integrity and confidentiality of the database.
Which software is affected by CVE-2025-12933?
CVE-2025-12933 affects SourceCodester Baby Care System version 1.0.
Is CVE-2025-12933 a remote vulnerability?
Yes, CVE-2025-12933 can be exploited remotely, allowing attackers to execute SQL injection attacks without physical access.