What is CVE-2025-67405?
A critical SQL Injection vulnerability has been identified in Sourcecodester CASAP Automated Enrollment System 1.0. This flaw affects the password update functionality in the `update_password.php` file via the `new_password` parameter. Immediate patching or temporary decommissioning of the affected system is strongly advised.
Azərbaycanca: Sourcecodester CASAP Automated Enrollment System 1.0 proqramında kritik SQL Injection zəifliyi aşkar edilib. Bu boşluq, `update_password.php` faylındakı `new_password` parametri vasitəsilə şifrə yeniləmə funksiyasına təsir edir. Təcili olaraq istehsalçı tərəfindən yamaq tətbiq edilməli və ya sistem müvəqqəti olaraq əlçatan olmayana qədər istifadədən çıxarılmalıdır.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: SourceCodester
FAQ2
Which version of Sourcecodester CASAP Automated Enrollment System is affected by CVE-2025-67405?
This critical SQL Injection vulnerability affects version 1.0 of Sourcecodester CASAP Automated Enrollment System.
Through which file and parameter is CVE-2025-67405 exploited?
The vulnerability is exploited through the password update function in the `update_password.php` file via the `new_password` parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.