What is CVE-2025-67403?
A SQL Injection vulnerability has been found in Sourcecodester CASAP Automated Enrollment System 1.0, specifically in the `update_class.php` file via the `class_name` parameter. This could allow an authenticated attacker to manipulate the database. Proper input validation should be implemented in `update_class.php`.
Azərbaycanca: Sourcecodester CASAP Automated Enrollment System 1.0-da `update_class.php` faylında `class_name` parametri vasitəsilə SQL Injection zəifliyi aşkar edilib. Bu zəiflik autentifikasiya olunmuş istifadəçiyə verilənlər bazasına müdaxilə etməyə imkan verə bilər. `update_class.php` faylında istifadəçi daxiletmələrinin düzgün yoxlanılması təmin edilməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: SourceCodester
FAQ2
In which file is the SQL Injection vulnerability located in Sourcecodester CASAP Automated Enrollment System 1.0?
The vulnerability is located in the `update_class.php` file, via the `class_name` parameter.
Does exploiting this CVE vulnerability require authentication?
Yes, the vulnerability can be exploited by an authenticated attacker.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.