VulnerabilityAnalyzed
CVE-2025-9002
A vulnerability was identified in Surbowl dormitory-management-php 1.0.
MEDIUM 5.5EPSS 0.55%
Does this matter?
Lower severity and a low EPSS score (0.55%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was identified in Surbowl dormitory-management-php 1.0. This affects an unknown part of the file login.php. The manipulation of the argument Account leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
- CVSS 4.0
- 5.5 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.55% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-89
- Affected
- surbowl/dormitory-management-php
- Source
- cna@vuldb.com
References
- https://github.com/fatdog957/CVE-/issues/1Exploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?ctiid.320031Permissions Required, VDB Entry
- https://vuldb.com/?id.320031Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.625595Exploit, Third Party Advisory, VDB Entry
- https://github.com/fatdog957/CVE-/issues/1Exploit, Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.