SQL Injection Vulnerability in Sourcecodester CASAP Automated Enrollment System
CVE-2025-67404
9.8CRITICAL
What is CVE-2025-67404?
The CASAP Automated Enrollment System version 1.0 developed by Sourcecodester is susceptible to SQL injection attacks via the 'save_stud.php' script. The vulnerability allows attackers to manipulate SQL queries by exploiting parameters such as 'fname', 'lname', and 'student_class'. This could result in unauthorized access to sensitive data or database manipulation, emphasizing the importance of securing user inputs to protect against such threats.
