What is CVE-2025-67407?
A SQL Injection vulnerability has been identified in Sourcecodester CASAP Automated Enrollment System 1.0, specifically in the `update_student.php` file via the `fname` and `student_class` parameters. This could allow an attacker to read or modify the database. Users should immediately apply the security patch provided by the vendor or conditionally isolate the affected system from the network.
Azərbaycanca: Sourcecodester CASAP Automated Enrollment System 1.0 proqramında `update_student.php` faylında `fname` və `student_class` parametrləri vasitəsilə SQL injection zəifliyi aşkarlanıb. Bu, təcavüzkara verilənlər bazasını oxumaq və ya manipulyasiya etmək imkanı verə bilər. İstifadəçilər dərhal provayder tərəfindən təqdim olunan təhlükəsizlik yamasını tətbiq etməli və ya şərti olaraq təsirlənən sistemi şəbəkədən təcrid etməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: SourceCodester
FAQ2
In which file of the Sourcecodester CASAP Automated Enrollment System was the CVE-2025-67407 vulnerability discovered?
This SQL injection vulnerability was discovered in the `update_student.php` file via the `fname` and `student_class` parameters.
What can an attacker do by exploiting the CVE-2025-67407 vulnerability?
An attacker could read or modify the database by exploiting this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.