CVE-2025-8986: SourceCodester COVID 19 Testing Management System search-report-result.php sql injection
A vulnerability was determined in SourceCodester COVID 19 Testing Management System 1.0. Affected by this issue is some unknown functionality of the file /search-report-result.php. The manipulation of the argument serachdata leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8986?
CVE-2025-8986 is classified as a high severity vulnerability due to its SQL injection risk.
How do I fix CVE-2025-8986?
To fix CVE-2025-8986, sanitize and validate all user inputs, particularly the search data parameter in /search-report-result.php.
What impact does CVE-2025-8986 have on systems?
CVE-2025-8986 allows attackers to manipulate SQL queries, leading to potential data leakage, modification, or deletion.
Is CVE-2025-8986 exploitable remotely?
Yes, CVE-2025-8986 can be exploited remotely, allowing attackers to execute SQL injection attacks from any location.
Who is affected by CVE-2025-8986?
Users of SourceCodester COVID 19 Testing Management System version 1.0 are affected by CVE-2025-8986.