CVE-2025-2655: SourceCodester AC Repair and Services System Users.php delete_users sql injection
A vulnerability was detected in SourceCodester AC Repair and Services System 1.0. The affected element is the function saveusers/deleteusers of the file /classes/Users.php. Performing manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. Other parameters might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2655?
CVE-2025-2655 has been declared as critical due to its potential for SQL injection.
How does CVE-2025-2655 affect the SourceCodester AC Repair and Services System?
CVE-2025-2655 affects the save_users function in the /classes/Users.php file, allowing for SQL injection through manipulated parameters.
What are the potential consequences of exploiting CVE-2025-2655?
Exploiting CVE-2025-2655 could allow attackers to access, modify, or delete sensitive data in the SourceCodester AC Repair and Services System database.
How do I fix CVE-2025-2655?
To fix CVE-2025-2655, review and sanitize all inputs to the save_users function, implementing prepared statements to mitigate SQL injection risks.
What versions of software are affected by CVE-2025-2655?
CVE-2025-2655 affects SourceCodester AC Repair and Services System version 1.0.