What is CVE-2025-67406?
A critical SQL Injection vulnerability was found in SourceCodester Advocate Office Management System 1.0, specifically in the `control/activate_case.php` file via the `id` parameter. This flaw allows remote attackers to execute arbitrary code. Affected systems should be urgently updated or the vulnerable input vector protected.
Azərbaycanca: SourceCodester Advocate Office Management System 1.0 proqramında kritik SQL Injection zəifliyi aşkar edilib. Bu boşluq `control/activate_case.php` faylındakı `id` parametri vasitəsilə uzaqdan kod icrasına imkan verir. Təsirə məruz qalan sistem dərhal yenilənməli və ya həssas giriş nöqtələri məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
In which file of SourceCodester Advocate Office Management System is the CVE-2025-67406 vulnerability located?
This critical SQL Injection vulnerability is found in the `control/activate_case.php` file.
What can a remote attacker achieve by exploiting CVE-2025-67406?
An attacker can achieve remote code execution (RCE) by performing SQL Injection through the `id` parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.