CVE-2025-2654: SourceCodester AC Repair and Services System manage_service.php sql injection
Published Mar 23, 2025
·Updated
A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/services/manageservice.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Sourcecodester AC Repair and Services System
oretnom23 Ac Repair And Services System=1.0
Event History
Mar 23, 2025
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
May 23, 58462
Event
via NVD·10:44 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-2654?
CVE-2025-2654 is classified as a critical vulnerability.
2
What type of vulnerability is CVE-2025-2654?
CVE-2025-2654 is a SQL injection vulnerability.
3
Which file is affected by CVE-2025-2654?
CVE-2025-2654 affects the file /admin/services/manage_service.php.
4
How do I fix CVE-2025-2654?
To fix CVE-2025-2654, ensure proper validation and sanitization of user inputs in the affected file.
5
What could be the impact of exploiting CVE-2025-2654?
Exploiting CVE-2025-2654 may allow an attacker to manipulate the database and execute arbitrary SQL commands.