SQL Injection Vulnerability in CASAP Automated Enrollment System by Sourcecodester
CVE-2025-67403
9.8CRITICAL
What is CVE-2025-67403?
The CASAP Automated Enrollment System version 1.0, developed by Sourcecodester, contains a SQL injection vulnerability that stems from inadequate input validation in the update_class.php file. This occurs specifically through the class_name parameter, allowing malicious users to execute arbitrary SQL code. Successful exploitation of this vulnerability could lead to unauthorized access to the database, data leakage, or manipulation of stored information.
