What is CVE-2025-67408?
A critical SQL Injection vulnerability was discovered in Sourcecodester CASAP Automated Enrollment System version 1.0. It can be exploited via the `status` parameter in the `/save_user.php` file. It is recommended to immediately apply the vendor patch or isolate the affected system from the network.
Azərbaycanca: Sourcecodester CASAP Automated Enrollment System 1.0 versiyasında kritik SQL Injection zəifliyi aşkar edilib. /save_user.php faylındakı 'status' parametri vasitəsilə həyata keçirilə bilər. Dərhal təchizatçı tərəfindən təqdim ediləcək patchi tətbiq etmək və ya təsirlənən sistemi şəbəkədən izolyasiya etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: SourceCodester
FAQ2
Which version of Sourcecodester CASAP Automated Enrollment System is affected by CVE-2025-67408?
This vulnerability affects version 1.0 of Sourcecodester CASAP Automated Enrollment System.
Which file and parameter are targeted to exploit CVE-2025-67408?
This SQL Injection vulnerability can be exploited via the `status` parameter in the `/save_user.php` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.