CVE Vulnerabilities

CVE-2025-2601

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Published: Mar 21, 2025 | Modified: May 14, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This affects an unknown part of the file activate_reg.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Weakness 

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Affected Software 

Name Vendor Start Version End Version
Advocate_office_management_system Mayurik 1.0 (including) 1.0 (including)

Potential Mitigations 

References