CVE-2025-9930: 1000projects Beauty Parlour Management System contact-us.php sql injection
A security vulnerability has been detected in 1000projects Beauty Parlour Management System 1.0. This impacts an unknown function of the file /admin/contact-us.php. The manipulation of the argument mobnumber leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9930?
CVE-2025-9930 is categorized as a high severity vulnerability due to its potential for SQL injection and remote exploitation.
How do I fix CVE-2025-9930?
To fix CVE-2025-9930, you should sanitize and validate the input for the mobnumber parameter to prevent SQL injection.
What systems are affected by CVE-2025-9930?
CVE-2025-9930 affects the 1000projects Beauty Parlour Management System version 1.0.
Can CVE-2025-9930 be exploited remotely?
Yes, CVE-2025-9930 can be exploited remotely through the vulnerable contact-us.php file.
What type of vulnerability is CVE-2025-9930?
CVE-2025-9930 is specifically an SQL injection vulnerability.