CVE-2025-6868: SourceCodester Simple Company Website manage.php sql injection
A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/clients/manage.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6868?
CVE-2025-6868 has been classified as a critical vulnerability.
How does CVE-2025-6868 affect the Simple Company Website?
CVE-2025-6868 allows for SQL injection by manipulating the ID argument in the /admin/clients/manage.php file.
Is remote access possible for CVE-2025-6868?
Yes, CVE-2025-6868 can be exploited remotely.
Which version of the SourceCodester Simple Company Website is affected by CVE-2025-6868?
Only version 1.0 of the SourceCodester Simple Company Website is affected by CVE-2025-6868.
How do I fix CVE-2025-6868?
To fix CVE-2025-6868, sanitize and validate all user inputs to prevent SQL injection vulnerabilities.