CVE-2025-9764: itsourcecode Sports Management System resultdetails.php sql injection
A flaw has been found in itsourcecode Sports Management System 1.0. Impacted is an unknown function of the file /Admin/resultdetails.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9764?
CVE-2025-9764 is considered a high severity vulnerability due to its potential for SQL injection exploitation.
How does CVE-2025-9764 affect the Sports Management System?
CVE-2025-9764 affects the Sports Management System by allowing remote attackers to manipulate SQL queries through the ID argument in the /Admin/resultdetails.php file.
What are the potential consequences of exploiting CVE-2025-9764?
Exploiting CVE-2025-9764 may allow attackers to access or modify sensitive database information.
How do I fix CVE-2025-9764?
To fix CVE-2025-9764, it is recommended to validate and sanitize input parameters in the affected SQL query and upgrade to the latest version provided by the vendor.
Is there a patch available for CVE-2025-9764?
As of now, there is no specific patch released for CVE-2025-9764, so immediate remediation through code changes is necessary.