CVE-2025-6346: SourceCodester Advance Charity Management System fundDetails.php sql injection
A vulnerability was found in SourceCodester Advance Charity Management System 1.0. It has been classified as critical. This affects an unknown part of the file /members/fundDetails.php. The manipulation of the argument m06 leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6346?
CVE-2025-6346 has been classified as a critical vulnerability.
How does CVE-2025-6346 affect the SourceCodester Advance Charity Management System?
CVE-2025-6346 allows for SQL injection through manipulation of the argument 'm06' in the file /members/fundDetails.php.
What are the potential consequences of exploiting CVE-2025-6346?
Exploitation of CVE-2025-6346 could lead to unauthorized access to the database and manipulation of sensitive data.
How can CVE-2025-6346 be mitigated?
Mitigation of CVE-2025-6346 involves implementing prepared statements and parameterized queries to protect against SQL injection.
Is there an official patch for CVE-2025-6346 available?
As of now, there is no information about an official patch for CVE-2025-6346; users are advised to secure their systems immediately.