CVE-2025-9022: SourceCodester Online Bank Management System statements.php sql injection
A vulnerability was identified in SourceCodester Online Bank Management System up to 1.0. This issue affects some unknown processing of the file /bank/statements.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9022?
CVE-2025-9022 has a high severity rating due to its potential for SQL injection, which can allow attackers to manipulate database queries.
How do I fix CVE-2025-9022?
To fix CVE-2025-9022, it is essential to validate and sanitize user inputs before processing them in database queries.
What systems are affected by CVE-2025-9022?
CVE-2025-9022 affects the SourceCodester Online Bank Management System versions up to and including 1.0.
Can CVE-2025-9022 be exploited remotely?
Yes, CVE-2025-9022 can be exploited remotely through unauthorized access to the vulnerable file.
What impact can CVE-2025-9022 have on a system?
CVE-2025-9022 can lead to unauthorized data access, data manipulation, and potentially full control over the database.