CVE-2025-13298: itsourcecode Web-Based Internet Laboratory Management System controller.php sql injection
A vulnerability was detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. This affects an unknown function of the file /enrollment/controller.php. Performing a manipulation results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13298?
CVE-2025-13298 is considered a high-severity vulnerability due to its potential for remote SQL injection attacks.
How does CVE-2025-13298 exploit work?
CVE-2025-13298 exploits a vulnerability in the /enrollment/controller.php file that allows for SQL injection manipulation.
Who is affected by CVE-2025-13298?
CVE-2025-13298 affects users of itsourcecode Web-Based Internet Laboratory Management System version 1.0.
How do I fix CVE-2025-13298?
To fix CVE-2025-13298, update the itsourcecode Web-Based Internet Laboratory Management System to the latest version and implement proper input validation.
Is CVE-2025-13298 a remote vulnerability?
Yes, CVE-2025-13298 can be exploited remotely, allowing attackers to perform SQL injection from a remote location.