PT-2025-54219 · Itsourcecode · Society Management System
Bupt_2025201
·
Published
2025-12-30
·
Updated
2026-01-02
·
CVE-2025-15353
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
itsourcecode Society Management System version 1.0
Description
A flaw exists in the function
edit admin query located in the file /admin/edit admin query.php. Manipulation of the Username argument can lead to SQL injection. This issue is remotely exploitable. The exploit is publicly available.Recommendations
Apply any available updates to address the issue in the
edit admin query function. As a temporary workaround, consider restricting access to the /admin/edit admin query.php file. Avoid using the Username parameter in the affected function until the issue is resolved.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Society Management System