SQL Injection Vulnerability in itsourcecode Tailoring Management System
CVE-2025-0947
Key Information:
- Vendor
Itsourcecode
- Vendor
- CVE Published:
- 1 February 2025
Badges
What is CVE-2025-0947?
A SQL injection vulnerability has been identified in the itsourcecode Tailoring Management System 1.0, specifically within the expview.php file. This security issue arises from improper handling of the expid argument, allowing attackers to manipulate database queries. The flaw can be exploited remotely, enabling potential unauthorized access to sensitive data and the execution of malicious SQL commands. The vulnerability has been publicly disclosed, raising concerns for users of the affected system. It is critical for administrators to apply the necessary patches or updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
Tailoring Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.