CVE-2025-15354: itsourcecode Society Management System add_admin.php sql injection
A flaw has been found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the file /admin/addadmin.php. Executing manipulation of the argument Username can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15354?
CVE-2025-15354 is classified as a high-severity vulnerability due to its potential for remote SQL injection.
How do I fix CVE-2025-15354?
To fix CVE-2025-15354, sanitize and validate user inputs to prevent SQL injection in the /admin/add_admin.php file.
What impact does CVE-2025-15354 have on the affected software?
CVE-2025-15354 allows attackers to manipulate the Username argument, leading to unauthorized access and potential data breaches.
Is CVE-2025-15354 exploitable remotely?
Yes, CVE-2025-15354 can be exploited remotely, making it a significant threat if left unpatched.
Which component of the itsourcecode Society Management System does CVE-2025-15354 affect?
CVE-2025-15354 affects the /admin/add_admin.php file in the itsourcecode Society Management System.