
CVE-2025-3314 – SourceCodester Apartment Visitor Management System forgotpw.php sql injection
https://notcve.org/view.php?id=CVE-2025-3314
06 Apr 2025 — A vulnerability has been found in SourceCodester Apartment Visitor Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /forgotpw.php. The manipulation of the argument secode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/tongjt123/CVE/issues/1 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2025-3298 – SourceCodester Online Eyewear Shop Registration Master.php access control
https://notcve.org/view.php?id=CVE-2025-3298
05 Apr 2025 — A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product of the component Registration Handler. The manipulation of the argument email leads to improper access controls. The attack can be launched remotely. • https://vuldb.com/?id.303493 • CWE-266: Incorrect Privilege Assignment CWE-284: Improper Access Control •

CVE-2025-3297 – SourceCodester Online Eyewear Shop Master.php cross site scripting
https://notcve.org/view.php?id=CVE-2025-3297
05 Apr 2025 — A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /classes/Master.php?f=save_product. The manipulation of the argument brand leads to cross site scripting. It is possible to launch the attack remotely. • https://github.com/foreverfeifei/cve/blob/main/xss.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2025-3296 – SourceCodester Online Eyewear Shop Users.php sql injection
https://notcve.org/view.php?id=CVE-2025-3296
05 Apr 2025 — A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=delete_customer. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. • https://github.com/foreverfeifei/cve/blob/main/sql.md • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2025-3244 – SourceCodester Web-based Pharmacy Product Management System Create User Page add-admin.php unrestricted upload
https://notcve.org/view.php?id=CVE-2025-3244
04 Apr 2025 — A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add-admin.php of the component Create User Page. The manipulation of the argument Avatar leads to unrestricted upload. The attack can be launched remotely. • https://github.com/6s6-630/CVE/blob/main/yaofang.md • CWE-284: Improper Access Control CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2025-3151 – SourceCodester Gym Management System signup.php sql injection
https://notcve.org/view.php?id=CVE-2025-3151
03 Apr 2025 — A vulnerability was found in SourceCodester Gym Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /signup.php. The manipulation of the argument user_name leads to sql injection. The attack may be launched remotely. • https://github.com/MiniSweetBeen/src/issues/5 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2025-3143 – SourceCodester Apartment Visitor Management System visitor-entry.php sql injection
https://notcve.org/view.php?id=CVE-2025-3143
03 Apr 2025 — A vulnerability classified as critical has been found in SourceCodester Apartment Visitor Management System 1.0. Affected is an unknown function of the file /visitor-entry.php. The manipulation of the argument visname/address leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/Lena-lyy/SQL/blob/main/SQL4.md • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2025-3142 – SourceCodester Apartment Visitor Management System add-apartment.php sql injection
https://notcve.org/view.php?id=CVE-2025-3142
03 Apr 2025 — A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /add-apartment.php. The manipulation of the argument buildingno leads to sql injection. The attack may be initiated remotely. • https://github.com/Lena-lyy/SQL/blob/main/SQL3.md • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2025-3141 – SourceCodester Online Medicine Ordering System manage_category.php sql injection
https://notcve.org/view.php?id=CVE-2025-3141
03 Apr 2025 — A vulnerability was found in SourceCodester Online Medicine Ordering System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /manage_category.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. • https://github.com/Lena-lyy/SQL/blob/main/SQL2.md • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2025-3140 – SourceCodester Online Medicine Ordering System view_category.php sql injection
https://notcve.org/view.php?id=CVE-2025-3140
03 Apr 2025 — A vulnerability was found in SourceCodester Online Medicine Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file /view_category.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. • https://github.com/Lena-lyy/SQL/blob/main/SQL1.md • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •