CVE-2025-11479

🟡 Monitoruj

Wstrzyknięcie SQL w SourceCodester Wedding Reservation Management System umożliwia zdalne ataki.

CVSS
7.3
EPSS
0.4%
Exploit
poc
Vendor
janobe
Opis źródłowy (NVD)

A security vulnerability has been detected in SourceCodester Wedding Reservation Management System 1.0. Impacted is the function insertReservation of the file function.php. Such manipulation of the argument number leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

exploit sql-injection Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2025-10-08 15:16:23 UTC
Ostatnia modyfikacja (NVD)2026-10-08 13:10:00 UTC
Referencje