CVE-2025-7860: code-projects Church Donation System login_admin.php sql injection
A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1.0. This issue affects some unknown processing of the file /members/loginadmin.php. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7860?
CVE-2025-7860 is classified as a critical vulnerability due to its potential for SQL injection.
How do I fix CVE-2025-7860?
To fix CVE-2025-7860, sanitize and validate user inputs in the /members/login_admin.php file to prevent SQL injection.
What is the impact of CVE-2025-7860?
The impact of CVE-2025-7860 includes unauthorized database access and manipulation, potentially leading to data breaches.
Which software is affected by CVE-2025-7860?
CVE-2025-7860 affects the Church Donation System version 1.0 developed by code-projects.
What kind of attack can be executed through CVE-2025-7860?
An attacker can execute SQL injection attacks by manipulating the Username argument in the login_admin.php file.