CVE-2025-9765: itsourcecode Sports Management System tournament_details.php sql injection
A vulnerability has been found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of the file /Admin/tournamentdetails.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9765?
CVE-2025-9765 has been classified as a high severity SQL injection vulnerability.
How do I fix CVE-2025-9765?
To fix CVE-2025-9765, sanitizing user inputs and parameterizing SQL queries in the affected file is essential.
What type of attack can CVE-2025-9765 facilitate?
CVE-2025-9765 can facilitate remote SQL injection attacks, potentially leading to unauthorized data access.
Which version of Sports Management System is affected by CVE-2025-9765?
CVE-2025-9765 affects version 1.0 of the itsourcecode Sports Management System.
Where is the vulnerability located in the Sports Management System for CVE-2025-9765?
The vulnerability in CVE-2025-9765 is located in the unknown function of the file /Admin/tournament_details.php.