CVE-2025-67405: SQL Injection
Published Jul 29, 2026
·Updated
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in updatepassword.php via the parameter newpassword.
Affected Software
1 affected component
Sourcecodester CASAP Automated Enrollment System=1.0
Event History
Jul 29, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-67405?
The severity of CVE-2025-67405 is rated high with a CVSS score of 7.3.
2
What type of vulnerability is CVE-2025-67405?
CVE-2025-67405 is an SQL Injection vulnerability affecting the update_password.php file.
3
How can I exploit CVE-2025-67405?
CVE-2025-67405 can be exploited by supplying malicious input in the new_password parameter to execute unauthorized SQL commands.
4
How do I fix CVE-2025-67405?
To fix CVE-2025-67405, sanitize and validate user inputs to prevent SQL injection in the update_password.php function.
5
What systems are affected by CVE-2025-67405?
CVE-2025-67405 affects Sourcecodester CASAP Automated Enrollment System version 1.0.