First published: Sun Mar 23 2025(Updated: )
A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/services/manage_service.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
AC Repair and Services System | ||
AC Repair and Services System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2654 is classified as a critical vulnerability.
CVE-2025-2654 is a SQL injection vulnerability.
CVE-2025-2654 affects the file /admin/services/manage_service.php.
To fix CVE-2025-2654, ensure proper validation and sanitization of user inputs in the affected file.
Exploiting CVE-2025-2654 may allow an attacker to manipulate the database and execute arbitrary SQL commands.