PT-2025-33421 · Sourcecodester · Covid19 Testing Management System

Zhuyi

·

Published

2025-08-14

·

Updated

2025-08-20

·

CVE-2025-8989

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SourceCodester COVID 19 Testing Management System version 1.0
Description: A SQL injection issue exists due to the manipulation of the mobilenumber argument in the processing of the /edit-phlebotomist.php file. The attack can be initiated remotely, and the exploit has been publicly disclosed. Other parameters may also be affected.
Recommendations: As a temporary workaround, consider restricting access to the /edit-phlebotomist.php file until a patch is available. Sanitize the mobilenumber input to prevent SQL injection attacks. Review the code for other potentially vulnerable parameters and apply appropriate input validation and sanitization techniques.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-8989

Affected Products

Covid19 Testing Management System