CVE-2025-8467: code-projects Wazifa System regcontrol.php sql injection
Published Aug 2, 2025
·Updated
A vulnerability was found in code-projects Wazifa System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /controllers/regcontrol.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Code-projects Wazifa System
Anisha Wazifa System=1.0
Event History
Aug 2, 2025
CVE Published
via MITRE·11:02 AM
Data Sourced
via MITRE·11:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Jun 19, 58473
Event
via NVD·09:13 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-8467?
The severity of CVE-2025-8467 is classified as critical.
2
How do I fix CVE-2025-8467?
To fix CVE-2025-8467, it is essential to validate and sanitize user input in the regcontrol.php file to prevent SQL injection.
3
What type of vulnerability is CVE-2025-8467?
CVE-2025-8467 is a SQL injection vulnerability.
4
Which component of Wazifa System is affected by CVE-2025-8467?
CVE-2025-8467 affects the functionality in the file /controllers/regcontrol.php.
5
Who is the vendor for the vulnerable product related to CVE-2025-8467?
The vendor for the vulnerable product is code-projects.