Surbowl · Dormitory-Management-Php · CVE-2025-9150
Name of the Vulnerable Software and Affected Versions:
Surbowl dormitory-management-php versions prior to 9f1d9d1f528cabffc66fda3652c56ff327fda317
Description:
A SQL injection issue exists in Surbowl dormitory-management-php. The issue is located in the `/admin/violation add.php` file, specifically through manipulation of the `id` parameter. This allows for remote exploitation. The product utilizes a rolling release system, and version information for affected or updated releases is not disclosed. This vulnerability only affects products that are no longer supported by the maintainer.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.