CVE Details
Basic Information
| Title | SourceCodester Best Salon Management System edit-services.php sql injection |
|---|---|
| Type | cve |
| Published | 2025-06-25T14:31:06.417Z |
| Last Seen |
Product Information
| Vendor | SourceCodester |
|---|---|
| Product | Best Salon Management System |
| Version | 1.0 |
CVSS Information
| Base Score | 5.3 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A SQL injection vulnerability in the edit-services.php file of SourceCodester Best Salon Management System 1.0 allows remote attackers to inject malicious SQL code via the editid parameter. This could lead to unauthorized data access or modification. The vulnerability has been publicly disclosed. |
|---|---|
| AI Severity | Medium |
| Vendor | SourceCodester |
| Product | Best Salon Management System |
| Affected Version | 1.0 |
Affected Products
- SourceCodester Best Salon Management System 1.0
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-89, CWE-74 |
| Bulletin Family |
References
Description
A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /panel/edit-services.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.