CVE-2025-26157
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
14/02/2025
Last modified:
14/02/2025
Description
A SQL Injection vulnerability was found in /bpms/index.php in Source Code and Project Beauty Parlour Management System V1.1, which allows remote attackers to execute arbitrary code via the name POST request parameter.
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM