SQL Injection Vulnerability in Best Salon Management System by SourceCodester
CVE-2025-6878

6.3MEDIUM

What is CVE-2025-6878?

A security vulnerability has been identified in the Best Salon Management System version 1.0 by SourceCodester, located specifically in the /panel/search-appointment.php file. This flaw allows an attacker to manipulate the 'searchdata' argument, leading to SQL injection attacks that can be executed remotely. As the exploit details have been publicly disclosed, it is crucial for users of the affected version to implement immediate security measures to safeguard their systems against potential threats.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2025-6878 : SQL Injection Vulnerability in Best Salon Management System by SourceCodester