SQL Injection Vulnerability in itsourcecode Tailoring Management System
CVE-2025-0945

5.3MEDIUM

Key Information:

Vendor
CVE Published:
1 February 2025

Badges

👾 Exploit Exists

Summary

A significant SQL injection vulnerability exists within the itsourcecode Tailoring Management System, specifically in the typedelete.php file. This flaw arises from improper handling of input parameters, particularly the argument 'id'. Attackers can exploit this vulnerability remotely, potentially leading to unauthorized access to the database. As the exploit has already been made public, it is crucial for users and administrators of the Tailoring Management System to take immediate action to mitigate the risk. Regular updates and monitoring are essential to safeguard against such vulnerabilities.

Affected Version(s)

Tailoring Management System 1.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-0945 : SQL Injection Vulnerability in itsourcecode Tailoring Management System | SecurityVulnerability.io