CVE-2025-6859: SourceCodester Best Salon Management System pro_sale.php sql injection
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file /panel/prosale.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6859?
CVE-2025-6859 has been classified as critical due to its potential for SQL injection exploitation.
How do I fix CVE-2025-6859?
To fix CVE-2025-6859, validate and sanitize input parameters used in the /panel/pro_sale.php file to prevent SQL injection.
Which system is affected by CVE-2025-6859?
CVE-2025-6859 affects the SourceCodester Best Salon Management System version 1.0.
What type of vulnerability is CVE-2025-6859?
CVE-2025-6859 is a SQL injection vulnerability that arises from improper handling of user input.
Can CVE-2025-6859 lead to data compromise?
Yes, CVE-2025-6859 can lead to unauthorized access to sensitive data due to SQL injection.