CVE-2025-6907: code-projects Car Rental System book_car.php sql injection
Published Jun 30, 2025
·Updated
A vulnerability classified as critical was found in code-projects Car Rental System 1.0. This vulnerability affects unknown code of the file /bookcar.php. The manipulation of the argument fname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Code-projects Car Rental System
Anisha Car Rental System=1.0
Event History
Jun 30, 2025
CVE Published
via MITRE·12:32 PM
Data Sourced
via MITRE·12:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 30, 57482
Event
via FIRST·01:36 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-6907?
CVE-2025-6907 is classified as critical due to its potential to allow remote SQL injection attacks.
2
How do I fix CVE-2025-6907?
To fix CVE-2025-6907, sanitize and validate all user input in the /book_car.php file to prevent SQL injection.
3
What software is affected by CVE-2025-6907?
CVE-2025-6907 affects the Code-projects Car Rental System version 1.0.
4
Can CVE-2025-6907 be exploited remotely?
Yes, CVE-2025-6907 can be exploited remotely.
5
What type of attack does CVE-2025-6907 involve?
CVE-2025-6907 involves SQL injection via manipulation of the fname argument.