CVE-2025-12926
MEDIUMSourceCodester Farm Management System 1.0 - SQL Injection
Title source: llmDescription
A weakness has been identified in SourceCodester Farm Management System 1.0. The affected element is an unknown function of the file /review.php. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.
References (5)
Scores
CVSS v3
6.3
EPSS
0.0004
EPSS Percentile
10.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-74
CWE-89
Status
published
Affected Products (1)
janobe/farm_management_system
Timeline
Published
Nov 10, 2025
Tracked Since
Feb 18, 2026