CVE-2025-1199

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 12, 2025
Updated: Feb 18, 2025
CWE ID 89
CWE ID 74

Summary

CVE-2025-1199 is a critical vulnerability affecting the Best Church Management Software 1.1 by SourceCodester. The issue lies in the /admin/app/role_crud.php file, where a sql injection vulnerability was discovered. Manipulation of the id argument can be exploited to inject malicious SQL commands. This vulnerability can be exploited remotely, allowing unauthorized access to sensitive data or even system takeover. The existence of this exploit has been made public, increasing the risk of attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share