What is CVE-2025-69947?
The SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection via the customeredit.php file. This flaw allows unauthorized database queries through the `id` parameter. To secure the system, input validation and parameterized queries should be implemented.
Azərbaycanca: SourceCodester Tailor Management System 1.0 proqramının customeredit.php faylında SQL Injection zəifliyi aşkarlanıb. Bu boşluq casus `id` parametri vasitəsilə məlumat bazasına icazəsiz sorğuların ötürülməsinə imkan yaradır. Sistemi qorumaq üçün məlumat bazası girişlərinin yoxlanması və parametrləşdirilmiş sorğulardan istifadə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: SourceCodester
FAQ2
Which file in SourceCodester Tailor Management System 1.0 contains the SQL Injection vulnerability?
The vulnerability is found in the customeredit.php file.
Which parameter can be used to perform this SQL Injection attack?
The attack can be carried out via the `id` parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.