CVE-2025-7212: itsourcecode Insurance Management System insertAgent.php sql injection
A vulnerability was found in itsourcecode Insurance Management System up to 1.0. It has been rated as critical. This issue affects some unknown processing of the file /insertAgent.php. The manipulation of the argument agentid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7212?
CVE-2025-7212 has been rated as critical.
How does CVE-2025-7212 affect the Insurance Management System?
CVE-2025-7212 allows for SQL injection through manipulation of the agent_id argument in the /insertAgent.php file.
What versions of the Insurance Management System are affected by CVE-2025-7212?
CVE-2025-7212 affects the itsourcecode Insurance Management System version up to and including 1.0.
How can I mitigate CVE-2025-7212?
To mitigate CVE-2025-7212, sanitize and validate inputs such as agent_id to prevent SQL injection.
Is CVE-2025-7212 exploitable remotely?
Yes, attacks exploiting CVE-2025-7212 can be initiated remotely.