CVE-2025-45956

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 29, 2025
Updated: May 14, 2025
CWE ID 89

Summary

CVE-2025-45956 is a SQL injection vulnerability discovered in manage_damage.php, a component of the Sourcecodester Computer Laboratory Management System v1.0. This issue enables authenticated attackers to execute arbitrary SQL commands by manipulating the "id" parameter. Successful exploitation could lead to unauthorized access to sensitive data or even system takeover. Users are strongly advised to update their systems to the latest available version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share