CVE-2025-13585: itsourcecode COVID Tracking System login.php sql injection
A vulnerability was detected in itsourcecode COVID Tracking System 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument code results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13585?
CVE-2025-13585 is classified as a high severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2025-13585?
To fix CVE-2025-13585, sanitize user inputs in the /login.php file to prevent SQL injection attacks.
Can CVE-2025-13585 be exploited remotely?
Yes, CVE-2025-13585 can be exploited remotely by an attacker manipulating the argument code.
What software is affected by CVE-2025-13585?
The software affected by CVE-2025-13585 is the Code-projects COVID Tracking System 1.0.
What type of vulnerability is CVE-2025-13585?
CVE-2025-13585 is an SQL injection vulnerability that can be triggered through improper processing of user input.