CVE-2025-6877: SourceCodester Best Salon Management System edit-category.php sql injection
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file /panel/edit-category.php. The manipulation of the argument editid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6877?
CVE-2025-6877 has been classified as a critical vulnerability.
What type of vulnerability is CVE-2025-6877?
CVE-2025-6877 is a SQL injection vulnerability that affects the editid argument in the file /panel/edit-category.php.
How can I fix CVE-2025-6877?
To mitigate CVE-2025-6877, sanitize and validate user input for the editid parameter to prevent SQL injection.
What software is affected by CVE-2025-6877?
CVE-2025-6877 affects the SourceCodester Best Salon Management System version 1.0.
Can CVE-2025-6877 be exploited remotely?
Yes, CVE-2025-6877 can be exploited remotely if the attacker can send requests to the vulnerable application.