CVE-2025-6604 Information

Description

A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/add-staff.php. The manipulation of the argument Name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Reference

https://github.com/Colorado-all/cve/blob/main/Best%20salon%20management%20system/SQL-5.md https://github.com/Colorado-all/cve/blob/main/Best%20salon%20management%20system/SQL-5.md https://vuldb.com/?ctiid.313821 https://vuldb.com/?id.313821 https://vuldb.com/?submit.601913 https://www.sourcecodester.com/

CNNVD-202506-3151 (Published: 2025-06-25)

Share on: