CVE-2025-13344: SourceCodester Train Station Ticketing System ajax.php sql injection
A weakness has been identified in SourceCodester Train Station Ticketing System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=login. This manipulation of the argument Username causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13344?
CVE-2025-13344 is classified as a high-severity SQL injection vulnerability.
How do I fix CVE-2025-13344?
To fix CVE-2025-13344, ensure proper input validation and parameterized queries for the login functionality.
What systems are affected by CVE-2025-13344?
CVE-2025-13344 affects SourceCodester Train Station Ticketing System version 1.0.
Can CVE-2025-13344 be exploited remotely?
Yes, CVE-2025-13344 can be exploited remotely through the login functionality.
What type of attack does CVE-2025-13344 involve?
CVE-2025-13344 involves SQL injection attacks through manipulation of the Username parameter.