Senayan · Slims · CVE-2025-22980
**Name of the Vulnerable Software and Affected Versions**
Senayan Library Management System SLiMS 9 Bulian version 9.6.1
**Description**
A SQL Injection issue exists in the loan form on the /admin/modules/circulation/loan.php endpoint, specifically via the `tempLoanID` parameter. This allows for potential SQL injection attacks.
**Recommendations**
For Senayan Library Management System SLiMS 9 Bulian version 9.6.1, consider restricting access to the `/admin/modules/circulation/loan.php` endpoint until a patch is available. As a temporary workaround, avoid using the `tempLoanID` parameter in the loan form to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.