CVE-2025-9702: SourceCodester Simple Cafe Billing System sales_report.php sql injection
A vulnerability was identified in SourceCodester Simple Cafe Billing System 1.0. This affects an unknown function of the file /salesreport.php. The manipulation of the argument month leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9702?
CVE-2025-9702 is classified as a high-severity SQL injection vulnerability.
How do I fix CVE-2025-9702?
To mitigate CVE-2025-9702, validate and sanitize user input in the sales_report.php file to prevent SQL injection.
What affects CVE-2025-9702?
CVE-2025-9702 affects the SourceCodester Simple Cafe Billing System 1.0.
Can CVE-2025-9702 be exploited remotely?
Yes, CVE-2025-9702 can be exploited remotely by manipulating the month argument in the affected file.
What type of vulnerability is CVE-2025-9702?
CVE-2025-9702 is an SQL injection vulnerability that allows attackers to manipulate database queries.