CVE-2025-9156: itsourcecode Sports Management System sports.php sql injection
A vulnerability was found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of the file /Admin/sports.php. Performing manipulation of the argument code results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9156?
CVE-2025-9156 has a high severity due to the potential for remote SQL injection exploitation.
How do I fix CVE-2025-9156?
To fix CVE-2025-9156, validate and sanitize input parameters in the /Admin/sports.php file to prevent SQL injection.
What impact does CVE-2025-9156 have on my system?
CVE-2025-9156 can allow attackers to manipulate database queries, leading to data theft or corruption.
Can CVE-2025-9156 be exploited remotely?
Yes, CVE-2025-9156 can be exploited remotely, making it critical to address as soon as possible.
Is CVE-2025-9156 specific to a particular version of the software?
Yes, CVE-2025-9156 specifically affects version 1.0 of the itsourcecode Sports Management System.