CVE-2025-8973: SourceCodester Cashier Queuing System Actions.php sql injection
A vulnerability has been found in SourceCodester Cashier Queuing System 1.0. Affected is an unknown function of the file /Actions.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8973?
CVE-2025-8973 has a high severity due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-8973?
To fix CVE-2025-8973, it is recommended to validate user inputs and use prepared statements for database queries.
What systems are affected by CVE-2025-8973?
CVE-2025-8973 affects SourceCodester Cashier Queuing System version 1.0.
Can CVE-2025-8973 be exploited remotely?
Yes, CVE-2025-8973 can be exploited remotely by manipulating the 'Username' argument.
What is the nature of the vulnerability in CVE-2025-8973?
The nature of CVE-2025-8973 is a SQL injection vulnerability which allows attackers to execute arbitrary SQL queries.