CVE-2025-9700: SourceCodester Online Book Store publisher_list.php sql injection
A flaw has been found in SourceCodester Online Book Store 1.0. This issue affects some unknown processing of the file /publisherlist.php. This manipulation of the argument pubid causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9700?
CVE-2025-9700 has been classified as a high severity vulnerability due to its potential for remote SQL injection exploitation.
How do I fix CVE-2025-9700?
To fix CVE-2025-9700, it is recommended to validate and sanitize all input parameters, particularly the pubid argument in /publisher_list.php.
Who is affected by CVE-2025-9700?
CVE-2025-9700 affects users of SourceCodester Online Book Store version 1.0.
What type of vulnerability is CVE-2025-9700?
CVE-2025-9700 is a SQL injection vulnerability that allows attackers to manipulate database queries.
Can CVE-2025-9700 be exploited remotely?
Yes, CVE-2025-9700 can be exploited remotely, making it particularly dangerous for web applications.