CVE-2025-9832: SourceCodester Food Ordering Management System register-router.php sql injection
A security vulnerability has been detected in SourceCodester Food Ordering Management System 1.0. Affected is an unknown function of the file /routers/register-router.php. Such manipulation of the argument phone leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9832?
CVE-2025-9832 is classified as a high-severity vulnerability due to the potential for SQL injection.
How do I fix CVE-2025-9832?
To fix CVE-2025-9832, sanitize and validate all user inputs, particularly the phone argument in the /routers/register-router.php file.
What types of attacks can exploit CVE-2025-9832?
CVE-2025-9832 can be exploited through remote SQL injection attacks targeting the register function.
Which systems are affected by CVE-2025-9832?
CVE-2025-9832 affects the SourceCodester Food Ordering Management System version 1.0.
Is CVE-2025-9832 easy to exploit?
Yes, exploiting CVE-2025-9832 is relatively easy for attackers familiar with SQL injection techniques.