SQL Injection Vulnerability in SourceCodester Apartment Visitor Management System
CVE-2025-3143
Key Information:
- Vendor
- Sourcecodester
- Vendor
- CVE Published:
- 3 April 2025
Badges
Summary
A SQL injection vulnerability exists in the SourceCodester Apartment Visitor Management System version 1.0, specifically in the /visitor-entry.php file. The manipulation of the 'visname' and 'address' parameters can allow an attacker to execute arbitrary SQL queries against the database remotely. This vulnerability can lead to unauthorized access to sensitive data and potentially compromise the entire system. It is essential for users of this system to apply the necessary security measures to protect against this exploitation.
Affected Version(s)
Apartment Visitor Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved