CVE-2025-7610: code-projects Electricity Billing System change_password.php sql injection
Published Jul 14, 2025
·Updated
A vulnerability was found in code-projects Electricity Billing System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /user/changepassword.php. The manipulation of the argument newpassword leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Code-projects Electricity Billing System
Anisha Electricity Billing System=1.0
Event History
Jul 14, 2025
CVE Published
via MITRE·02:02 PM
Data Sourced
via MITRE·02:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 20, 58473
Event
via NVD·05:18 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-7610?
CVE-2025-7610 is classified as a critical vulnerability.
2
How do I fix CVE-2025-7610?
To fix CVE-2025-7610, validate and sanitize inputs to the new_password argument to prevent SQL injection.
3
What systems are affected by CVE-2025-7610?
CVE-2025-7610 affects the Electricity Billing System 1.0 developed by code-projects.
4
What type of vulnerability is CVE-2025-7610?
CVE-2025-7610 is an SQL injection vulnerability.
5
What functionality is compromised in CVE-2025-7610?
CVE-2025-7610 compromises the functionality of the /user/change_password.php file.