CVE-2025-7125: itsourcecode Employee Management System editempeducation.php sql injection
A vulnerability classified as critical was found in itsourcecode Employee Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/editempeducation.php. The manipulation of the argument coursepg leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7125?
CVE-2025-7125 is classified as a critical vulnerability.
How do I fix CVE-2025-7125?
To fix CVE-2025-7125, sanitize and validate all user inputs in the /admin/editempeducation.php file to prevent SQL injection.
What software is affected by CVE-2025-7125?
CVE-2025-7125 affects the itsourcecode Employee Management System versions up to 1.0.
What type of vulnerability is CVE-2025-7125?
CVE-2025-7125 is an SQL injection vulnerability.
What functionality is exploited in CVE-2025-7125?
CVE-2025-7125 exploits the argument 'coursepg' in the /admin/editempeducation.php file.