CVE-2025-9766: itsourcecode Sports Management System facilitator.php sql injection
A vulnerability was found in itsourcecode Sports Management System 1.0. The impacted element is an unknown function of the file /Admin/facilitator.php. Performing manipulation of the argument code results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9766?
The severity of CVE-2025-9766 is considered high due to the potential for remote SQL injection attacks.
How do I fix CVE-2025-9766?
To fix CVE-2025-9766, it is recommended to sanitize user inputs and use prepared statements for database queries.
What software is affected by CVE-2025-9766?
CVE-2025-9766 affects the itsourcecode Sports Management System version 1.0.
Can CVE-2025-9766 be exploited remotely?
Yes, CVE-2025-9766 can be exploited remotely, allowing attackers to manipulate SQL queries.
What types of attacks can CVE-2025-9766 enable?
CVE-2025-9766 can enable SQL injection attacks, leading to data exposure or manipulation.