CVE-2025-9689: SourceCodester Advanced School Management System item_select sql injection
A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown function of the file /index.php/stock/itemselect. The manipulation of the argument q results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9689?
CVE-2025-9689 is considered a high severity vulnerability due to its potential for remote SQL injection.
How do I fix CVE-2025-9689?
To fix CVE-2025-9689, validate and sanitize all input data, particularly the 'q' parameter in the affected file.
What kind of attack can be executed using CVE-2025-9689?
CVE-2025-9689 allows for remote SQL injection attacks, which can lead to unauthorized database access.
Which version of SourceCodester Advanced School Management System is affected by CVE-2025-9689?
CVE-2025-9689 affects SourceCodester Advanced School Management System version 1.0.
Can I exploit CVE-2025-9689 remotely?
Yes, CVE-2025-9689 can be exploited remotely, making it particularly dangerous for users of the affected system.