CVE-2025-25914: SQL Injection
Published Mar 17, 2025
·Updated
SQL injection vulnerability in Online Exam Mastering System v.1.0 allows a remote attacker to execute arbitrary code via the fid parameter
Affected Software
2 affected components
Online Exam Mastering System Online Exam Mastering System
Carmelo Online Exam Mastering System=1.0
Event History
Mar 17, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25914?
CVE-2025-25914 is a high-severity SQL injection vulnerability that can lead to arbitrary code execution.
2
How do I fix CVE-2025-25914?
To fix CVE-2025-25914, sanitize the fid parameter inputs and implement prepared statements to prevent SQL injection.
3
Who is affected by CVE-2025-25914?
Any user or organization utilizing Online Exam Mastering System v.1.0 is vulnerable to CVE-2025-25914.
4
Can CVE-2025-25914 be exploited remotely?
Yes, CVE-2025-25914 allows remote attackers to exploit the vulnerability and execute arbitrary code.
5
What type of attack does CVE-2025-25914 involve?
CVE-2025-25914 involves an SQL injection attack that manipulates database queries to execute unauthorized commands.