SQL Injection Vulnerability in itsourcecode Tailoring Management System
CVE-2025-0945
5.3MEDIUM
Summary
A significant SQL injection vulnerability exists within the itsourcecode Tailoring Management System, specifically in the typedelete.php file. This flaw arises from improper handling of input parameters, particularly the argument 'id'. Attackers can exploit this vulnerability remotely, potentially leading to unauthorized access to the database. As the exploit has already been made public, it is crucial for users and administrators of the Tailoring Management System to take immediate action to mitigate the risk. Regular updates and monitoring are essential to safeguard against such vulnerabilities.
Affected Version(s)
Tailoring Management System 1.0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved