First published: Sun Mar 23 2025(Updated: )
A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been declared as critical. This vulnerability affects the function save_users of the file /classes/Users.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
AC Repair and Services System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2655 has been declared as critical due to its potential for SQL injection.
CVE-2025-2655 affects the save_users function in the /classes/Users.php file, allowing for SQL injection through manipulated parameters.
Exploiting CVE-2025-2655 could allow attackers to access, modify, or delete sensitive data in the SourceCodester AC Repair and Services System database.
To fix CVE-2025-2655, review and sanitize all inputs to the save_users function, implementing prepared statements to mitigate SQL injection risks.
CVE-2025-2655 affects SourceCodester AC Repair and Services System version 1.0.