CVE-2025-13300: itsourcecode Web-Based Internet Laboratory Management System controller.php sql injection
A vulnerability has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected is an unknown function of the file /settings/controller.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13300?
CVE-2025-13300 is classified as a serious vulnerability due to its potential for remote SQL injection.
How do I fix CVE-2025-13300?
To address CVE-2025-13300, update the itsourcecode Web-Based Internet Laboratory Management System to the latest patched version.
What types of attacks can be executed due to CVE-2025-13300?
CVE-2025-13300 allows attackers to execute SQL injection attacks remotely.
Which file is vulnerable in CVE-2025-13300?
The vulnerable function in CVE-2025-13300 is located in the file /settings/controller.php.
Who is affected by CVE-2025-13300?
Any user of the itsourcecode Web-Based Internet Laboratory Management System version 1.0 could potentially be affected by CVE-2025-13300.