Severity
5.3MEDIUMNVD
EPSS
0.1%
top 67.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 12
Latest updateSep 5

Description

A vulnerability classified as critical was found in code-projects Wazifa System 1.0. Affected by this vulnerability is an unknown functionality of the file /controllers/control.php. The manipulation of the argument to leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
code-projects Wazifa System control.php sql injection2025-02-12
GHSA
GHSA-f763-24vx-m6x9: A vulnerability classified as critical was found in code-projects Wazifa System 12025-02-12

📋Vendor Advisories

3
Red Hat
kernel: netfilter: nf_reject: don't leak dst refcount for loopback packets2025-09-05
Red Hat
kernel: pktgen: Avoid out-of-bounds access in get_imix_entries2025-01-31
Microsoft
LibTIFF tiff2ps resource consumption2022-04-12
CVE-2025-1210 — Injection in Wazifa System | cvebase