SQL Injection Vulnerability in SourceCodester Apartment Visitors Management System
CVE-2025-3120
Key Information:
- Vendor
- Sourcecodester
- Vendor
- CVE Published:
- 2 April 2025
Badges
Summary
A critical SQL injection vulnerability exists in the add-apartment.php file of the SourceCodester Apartment Visitors Management System 1.0. It allows attackers to manipulate the 'apartmentno' parameter, potentially leading to unauthorized access to the database. This issue can be exploited remotely, making it crucial for users to implement immediate security patches and monitor for signs of exploitation. Other parameters may also be at risk, highlighting the need for a thorough security review.
Affected Version(s)
Apartment Visitors Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved