CVE-2025-9705: SourceCodester Water Billing System paybill.php sql injection
A weakness has been identified in SourceCodester Water Billing System 1.0. Affected is an unknown function of the file /paybill.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9705?
CVE-2025-9705 is categorized as a critical vulnerability due to its potential for remote exploitation through SQL injection.
How do I fix CVE-2025-9705?
To mitigate CVE-2025-9705, implement parameterized queries or prepared statements to sanitize the input in the /paybill.php file.
Which systems are affected by CVE-2025-9705?
CVE-2025-9705 affects SourceCodester Water Billing System version 1.0.
What type of attack is described in CVE-2025-9705?
CVE-2025-9705 describes a SQL injection attack that can be exploited remotely through manipulation of the ID argument.
Can CVE-2025-9705 be exploited remotely?
Yes, CVE-2025-9705 allows for remote exploitation, making it critical for users to address immediately.