PT-2025-45602 · Sourcecodester · Baby Care System
Yuki77
·
Published
2025-11-10
·
Updated
2025-11-10
·
CVE-2025-12932
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SourceCodester Baby Care System version 1.0
Description
A SQL injection issue exists in SourceCodester Baby Care System 1.0. The issue affects functionality within the
/admin.php?id=inbox file. Manipulation of the msgid argument can lead to SQL injection. The attack can be initiated remotely. The exploit has been publicly disclosed.Recommendations
Sanitize or validate the
msgid parameter in the /admin.php?id=inbox file to prevent SQL injection. As a temporary workaround, restrict access to the /admin.php?id=inbox file.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Baby Care System