VulnerabilityAnalyzed
CVE-2025-12614
A weakness has been identified in SourceCodester Best House Rental Management System 1.0.
LOW 2.0EPSS 0.38%
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
A weakness has been identified in SourceCodester Best House Rental Management System 1.0. Impacted is the function delete_payment of the file /admin_class.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.
- CVSS 4.0
- 2.0 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-89
- Affected
- mayurik/best house rental management system
- Source
- cna@vuldb.com
References
- https://github.com/321190176/Best-house-rental-management-system-3/blob/main/report.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.330908Permissions Required, VDB Entry
- https://vuldb.com/?id.330908Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.678184Third Party Advisory, VDB Entry
- https://www.sourcecodester.com/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.