SQL Injection Vulnerability in itsourcecode Tailoring Management System
CVE-2025-0947
Summary
A SQL injection vulnerability has been identified in the itsourcecode Tailoring Management System 1.0, specifically within the expview.php file. This security issue arises from improper handling of the expid argument, allowing attackers to manipulate database queries. The flaw can be exploited remotely, enabling potential unauthorized access to sensitive data and the execution of malicious SQL commands. The vulnerability has been publicly disclosed, raising concerns for users of the affected system. It is critical for administrators to apply the necessary patches or updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
Tailoring Management System 1.0
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved