Description
A vulnerability was found in SourceCodester Company Website CMS 1.0. This affects an unknown part of the file /admin/reset-password.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
Problem types
Product status
Timeline
| 2025-11-22: | Advisory disclosed |
| 2025-11-22: | VulDB entry created |
| 2025-11-22: | VulDB entry last update |
Credits
admif.. (VulDB User)
References
github.com/miwangdemaoxianzhe/CVE/issues/1
vuldb.com/?id.333325 (VDB-333325 | SourceCodester Company Website CMS reset-password.php sql injection)
vuldb.com/?ctiid.333325 (VDB-333325 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.696637 (Submit #696637 | sourcecodester Company Website CMS V1.0 SQL InjectionSQL)
github.com/miwangdemaoxianzhe/CVE/issues/1
www.sourcecodester.com/