A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is some unknown functionality of the file /addCandidate.php. The manipulation of the argument candName results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be exploited.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sourcecodester
Sourcecodester interview Management System |
|
| Vendors & Products |
Sourcecodester
Sourcecodester interview Management System |
Mon, 10 Nov 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is some unknown functionality of the file /addCandidate.php. The manipulation of the argument candName results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be exploited. | |
| Title | SourceCodester Interview Management System addCandidate.php sql injection | |
| Weaknesses | CWE-74 CWE-89 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-11-10T13:02:06.050Z
Updated: 2025-11-10T13:02:06.050Z
Reserved: 2025-11-10T06:52:41.012Z
Link: CVE-2025-12939
No data.
Status : Awaiting Analysis
Published: 2025-11-10T13:15:44.713
Modified: 2025-11-12T16:19:59.103
Link: CVE-2025-12939
No data.