SQL Injection Vulnerability in SourceCodester Online Book Store Software
CVE-2025-9700
Key Information:
- Vendor
Sourcecodester
- Status
- Vendor
- CVE Published:
- 30 August 2025
Badges
What is CVE-2025-9700?
A vulnerability in SourceCodester Online Book Store version 1.0 has been detected, specifically in the file /publisher_list.php. An attacker can manipulate the pubid argument to perform SQL injection attacks, potentially allowing unauthorized access to the database. This flaw can be exploited remotely, posing a significant risk to users of the software. Users are advised to implement security measures and consider updates to mitigate the risk associated with this vulnerability.
Affected Version(s)
Online Book Store 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved