CVE-2025-7138: SourceCodester Best Salon Management System admin-profile.php sql injection
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /panel/admin-profile.php. The manipulation of the argument adminname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7138?
CVE-2025-7138 has been declared as critical.
How does CVE-2025-7138 affect the SourceCodester Best Salon Management System?
CVE-2025-7138 affects the /panel/admin-profile.php file, allowing SQL injection through the adminname parameter.
What type of attack can be initiated due to CVE-2025-7138?
An attacker can initiate an SQL injection attack due to the vulnerability in CVE-2025-7138.
How can I fix CVE-2025-7138?
To fix CVE-2025-7138, it is advised to sanitize and validate the input for the adminname parameter in the affected file.
What version of the software is affected by CVE-2025-7138?
CVE-2025-7138 affects SourceCodester Best Salon Management System version 1.0.