CVE-2025-6581: SourceCodester Best Salon Management System add-customer.php sql injection
A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-customer.php. The manipulation of the argument name/email/mobilenum/gender/details/dob/marriagedate leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6581?
CVE-2025-6581 is classified as a critical vulnerability.
What components are affected by CVE-2025-6581?
CVE-2025-6581 affects the file /add-customer.php within the SourceCodester Best Salon Management System.
How can I mitigate the risks of CVE-2025-6581?
To mitigate risks from CVE-2025-6581, review and secure the input handling in the affected file to prevent unauthorized input manipulation.
Is there a patch available for CVE-2025-6581?
As of now, there is no specified patch available for CVE-2025-6581; refer to the vendor for updates.
What type of attacks can CVE-2025-6581 facilitate?
CVE-2025-6581 can facilitate input manipulation attacks, potentially leading to data exposure or unauthorized actions.