CVE-2025-8985: SourceCodester COVID 19 Testing Management System profile.php sql injection
A vulnerability was found in SourceCodester COVID 19 Testing Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8985?
CVE-2025-8985 is classified as a SQL Injection vulnerability which can lead to unauthorized access to the database.
How do I fix CVE-2025-8985?
To fix CVE-2025-8985, sanitize user inputs and use prepared statements to prevent SQL injection.
What software is affected by CVE-2025-8985?
CVE-2025-8985 affects the SourceCodester COVID 19 Testing Management System version 1.0.
Can CVE-2025-8985 be exploited remotely?
Yes, CVE-2025-8985 can be exploited remotely by manipulating the mobilenumber argument in the profile.php file.
What type of attack is associated with CVE-2025-8985?
CVE-2025-8985 is associated with an SQL injection attack.