Junglewise Threat Intelligence

CVE-2025-67408: Sourcecodester CASAP Automated Enrollment System SQL injection in save_user.php

CVE-2025-67408 · Severity: info · CVSS 7.5 · Published 2026-07-29

Technologies: SourceCodester CASAP Automated Enrollment System. Vendors: SourceCodester.

Executive brief

The CASAP Automated Enrollment System, a web application used for managing student registrations, contains a security flaw that could allow unauthorized access to its database. By sending specially crafted requests to the user management component, an attacker could potentially view sensitive information such as user credentials or student records. This could lead to a significant data breach and compromise the integrity of the enrollment process.

Technical details

A SQL injection vulnerability exists in Sourcecodester CASAP Automated Enrollment System 1.0 within the '/save_user.php' endpoint. The application fails to properly sanitize the 'status' parameter before incorporating it into a database query. A remote attacker can exploit this by sending a crafted HTTP request to execute arbitrary SQL commands. This could allow for unauthorized data extraction from the backend database. The vulnerability was identified via automated taint analysis.

Affected products

  • Sourcecodester CASAP Automated Enrollment System 1.0

Timeline

  • 2026-07-29: disclosed: Initial publication of CVE-2025-67408

References

Related threats