PT-2025-43981 · Unknown · Sourcecodester Point Of Sales

Yongjie Feng

·

Published

2025-10-27

·

Updated

2025-11-03

·

CVE-2025-12294

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Point of Sales version 1.0
Description A security flaw exists in SourceCodester Point of Sales version 1.0. The issue involves a SQL injection affecting an unknown function within the /delete category.php file. Manipulation of the ID argument allows for remote exploitation. The exploit has been publicly released.
Recommendations For SourceCodester Point of Sales version 1.0, restrict or disable the use of the /delete category.php file as a temporary mitigation. Avoid using the ID parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-12294

Affected Products

Sourcecodester Point Of Sales