CVE-2025-6860
MEDIUMSourceCodester Best Salon Management System 1.0 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-6860. PoCs published by byteReaper77.
AI-analyzed exploit summary This repository contains a functional C-based exploit for CVE-2025-6860, targeting SQL injection in `staff_commision.php` via `fromdate` and `todate` parameters. It includes payload rotation, user-agent cycling, and response analysis for SQL error patterns.
Description
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /panel/staff_commision.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Exploits (1)
This repository contains a functional C-based exploit for CVE-2025-6860, targeting SQL injection in `staff_commision.php` via `fromdate` and `todate` parameters. It includes payload rotation, user-agent cycling, and response analysis for SQL error patterns.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L