Junglewise Threat Intelligence

CVE-2025-67405: Sourcecodester CASAP Automated Enrollment System SQL injection in update_password.php

CVE-2025-67405 · Severity: info · Published 2026-07-29

Technologies: SourceCodester CASAP Automated Enrollment System. Vendors: SourceCodester.

Executive brief

Sourcecodester CASAP Automated Enrollment System, a software used for managing student registrations, contains a security flaw in its password update functionality. An attacker can exploit this to send malicious commands to the underlying database. This could lead to unauthorized access to sensitive student records, data theft, or the ability to modify administrative credentials.

Technical details

A SQL injection vulnerability exists in Sourcecodester CASAP Automated Enrollment System 1.0 within the 'update_password.php' component. The application fails to properly sanitize the 'new_password' parameter before using it in a database query. A remote attacker can exploit this by sending specially crafted SQL commands to the server. Successful exploitation could allow the attacker to bypass authentication, read sensitive data from the database, or modify database records. The vulnerability was identified via automated taint analysis.

Affected products

  • Sourcecodester CASAP Automated Enrollment System 1.0

Timeline

  • 2026-07-29: disclosed: Initial NVD publication date

References

Related threats