CVE-2025-13299: itsourcecode Web-Based Internet Laboratory Management System controller.php sql injection
A flaw has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. This impacts an unknown function of the file /user/controller.php. Executing a manipulation can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13299?
CVE-2025-13299 is rated as a critical vulnerability due to the risk of SQL injection.
How do I fix CVE-2025-13299?
To fix CVE-2025-13299, sanitize user inputs in the /user/controller.php file to prevent SQL injection.
What are the potential impacts of CVE-2025-13299?
Exploiting CVE-2025-13299 can lead to unauthorized access to the database and possible data breaches.
Can CVE-2025-13299 be exploited remotely?
Yes, CVE-2025-13299 can be exploited remotely by manipulating inputs sent to the vulnerable function.
What software is affected by CVE-2025-13299?
CVE-2025-13299 affects the itsourcecode Web-Based Internet Laboratory Management System version 1.0.