CVE-2025-22980: SQL Injection
Published Jan 22, 2025
·Updated
A SQL Injection vulnerability exists in Senayan Library Management System SLiMS 9 Bulian 9.6.1 via the tempLoanID parameter in the loan form on /admin/modules/circulation/loan.php.
Affected Software
2 affected components
Senayan Library Management System SLiMS
Slims Senayan Library Management System Bulian=9.6.1
Event History
Jan 22, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-22980?
CVE-2025-22980 is a critical SQL Injection vulnerability that can allow unauthorized access to sensitive data.
2
How do I fix CVE-2025-22980?
To fix CVE-2025-22980, sanitize and validate user inputs on the tempLoanID parameter to prevent SQL Injection.
3
What software is affected by CVE-2025-22980?
CVE-2025-22980 affects the Senayan Library Management System SLiMS version 9 Bulian 9.6.1.
4
What is the impact of CVE-2025-22980?
The impact of CVE-2025-22980 includes potential exposure of sensitive data and unauthorized database queries.
5
Is there a workaround for CVE-2025-22980?
Currently, the best workaround for CVE-2025-22980 is to restrict access to the loan form until a patch is applied.