SQL Injection Vulnerability in CASAP Automated Enrollment System by Sourcecodester
CVE-2025-67407
7.3HIGH
What is CVE-2025-67407?
The CASAP Automated Enrollment System 1.0 is susceptible to an SQL Injection vulnerability located in the update_student.php file. Attackers can exploit this flaw by manipulating the fname and student_class parameters, potentially allowing unauthorized access to the database and manipulation of sensitive data. It is crucial for users of this system to implement security measures to mitigate this risk.
