Record summary

CVE-2025-12208 has a selected CVSS score of 6.9 (medium).

Description

A vulnerability was found in SourceCodester Best House Rental Management System 1.0. This impacts the function login2 of the file /admin_class.php. Performing manipulation of the argument Username results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 28, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List1.0affected

References

6
VDB-329878 | SourceCodester Best House Rental Management System admin_class.php login2 sql injectionvdb entryTechnical description
https://vuldb.com/?id.329878