Record summary

CVE-2025-12597 has a selected CVSS score of 5.1 (medium).

Description

A vulnerability was detected in SourceCodester Best House Rental Management System 1.0. Affected by this vulnerability is the function save_category of the file /admin_class.php. Performing manipulation of the argument Name results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 3, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List1.0affected

References

6
VDB-330892 | SourceCodester Best House Rental Management System admin_class.php save_category sql injectionvdb entryTechnical description
https://vuldb.com/?id.330892