CVE-2025-9690: SourceCodester Advanced School Management System vendordetails sql injection
A flaw has been found in SourceCodester Advanced School Management System 1.0. This affects an unknown function of the file /index.php/stock/vendordetails. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9690?
CVE-2025-9690 has been classified as a critical vulnerability due to its potential for remote exploitation via SQL injection.
How do I fix CVE-2025-9690?
To mitigate CVE-2025-9690, it is recommended to sanitize and validate all user inputs and upgrade to the patched version of the SourceCodester Advanced School Management System.
What are the potential impacts of CVE-2025-9690?
CVE-2025-9690 could lead to unauthorized access to the database, data leakage, and possibly full system compromise.
Which versions of the SourceCodester Advanced School Management System are affected by CVE-2025-9690?
CVE-2025-9690 affects version 1.0 of the SourceCodester Advanced School Management System.
Can CVE-2025-9690 be exploited remotely?
Yes, CVE-2025-9690 can be exploited remotely, making it particularly dangerous for exposed instances.