What is CVE-2025-67404?
A SQL Injection vulnerability exists in Sourcecodester CASAP Automated Enrollment System 1.0, specifically in the `save_stud.php` file via the `fname`, `lname`, and `student_class` parameters. This could allow attackers unauthorized access to the database. Users should immediately implement stricter input validation.
Azərbaycanca: Sourcecodester CASAP Automated Enrollment System 1.0 proqramında `save_stud.php` faylındakı `fname`, `lname` və `student_class` parametrləri vasitəsilə SQL Injection zəifliyi aşkarlanıb. Bu, təcavüzkarlara verilənlər bazasına icazəsiz giriş imkanı verə bilər. İstifadəçilər təcili olaraq daxil olan məlumatların yoxlanılmasını gücləndirməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: SourceCodester
FAQ2
Which file in Sourcecodester CASAP Automated Enrollment System 1.0 contains the SQL Injection vulnerability?
The vulnerability exists in the `save_stud.php` file.
Which parameters can an attacker exploit to leverage this SQL Injection vulnerability?
Attackers can exploit the `fname`, `lname`, and `student_class` parameters.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.