PT-2025-54219 · Itsourcecode · Society Management System

Bupt_2025201

·

Published

2025-12-30

·

Updated

2026-01-02

·

CVE-2025-15353

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions itsourcecode Society Management System version 1.0
Description A flaw exists in the function edit admin query located in the file /admin/edit admin query.php. Manipulation of the Username argument can lead to SQL injection. This issue is remotely exploitable. The exploit is publicly available.
Recommendations Apply any available updates to address the issue in the edit admin query function. As a temporary workaround, consider restricting access to the /admin/edit admin query.php file. Avoid using the Username parameter in the affected function until the issue is resolved.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-15353

Affected Products

Society Management System