CVE-2025-6905: code-projects Car Rental System signup.php sql injection
A vulnerability, which was classified as critical, has been found in code-projects Car Rental System 1.0. This issue affects some unknown processing of the file /signup.php. The manipulation of the argument fname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6905?
CVE-2025-6905 is classified as a critical vulnerability due to the potential for remote SQL injection.
How do I fix CVE-2025-6905?
To fix CVE-2025-6905, sanitize and validate all input parameters in the /signup.php file to prevent SQL injection.
What are the potential impacts of CVE-2025-6905?
If exploited, CVE-2025-6905 can lead to unauthorized access to the database and manipulation of sensitive data.
Is CVE-2025-6905 exploitable remotely?
Yes, CVE-2025-6905 can be exploited remotely using crafted requests to the affected /signup.php file.
Which software is affected by CVE-2025-6905?
CVE-2025-6905 affects the Code-projects Car Rental System version 1.0.