CVE-2025-15353: itsourcecode Society Management System edit_admin_query.php edit_admin_query sql injection
A vulnerability was detected in itsourcecode Society Management System 1.0. Impacted is the function editadminquery of the file /admin/editadminquery.php. Performing manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15353?
CVE-2025-15353 is classified as a critical vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-15353?
To fix CVE-2025-15353, sanitize all user inputs in the edit_admin_query function to prevent SQL injection.
Can CVE-2025-15353 be exploited remotely?
Yes, CVE-2025-15353 can be exploited remotely by manipulating the Username argument.
Which software is affected by CVE-2025-15353?
CVE-2025-15353 affects itsourcecode Society Management System version 1.0.
What kind of attack is associated with CVE-2025-15353?
CVE-2025-15353 is associated with SQL injection attacks.