SQL Injection Vulnerability in SourceCodester Water Billing System 1.0
CVE-2025-9704
Key Information:
- Vendor
Sourcecodester
- Status
- Vendor
- CVE Published:
- 30 August 2025
Badges
What is CVE-2025-9704?
A security vulnerability has been identified in the SourceCodester Water Billing System 1.0. This flaw resides within an unspecified function of the file viewbill.php, where improper handling of the 'ID' argument allows for SQL injection attacks. Malicious actors can exploit this vulnerability to execute unauthorized SQL commands, potentially leading to data breaches. The exploit code is publicly available, highlighting the urgency of addressing this issue to mitigate threats from remote attackers.
Affected Version(s)
Water Billing System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved