SQL Injection Vulnerability in Modern Loan Management System by SourceCodester
CVE-2025-69946
9.8CRITICAL
What is CVE-2025-69946?
The Modern Loan Management System developed by SourceCodester contains a SQL Injection vulnerability in the ajaxData.php file. This issue arises due to insufficient validation and sanitization of user inputs through parameters such as district_id, division_id, region_id, and ward_id. An attacker could exploit this flaw to execute arbitrary SQL queries, potentially allowing unauthorized access to sensitive data or manipulation of the database.
