CVE-2025-9305Injection in Online Bank Management System

Severity
6.9MEDIUMNVD
EPSS
0.0%
top 87.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 21

Description

A security vulnerability has been detected in SourceCodester Online Bank Management System 1.0. The affected element is an unknown function of the file /bank/mnotice.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

🔴Vulnerability Details

2
GHSA
GHSA-vvwr-c8hj-fmm7: A security vulnerability has been detected in SourceCodester Online Bank Management System 12025-08-21
CVEList
SourceCodester Online Bank Management System mnotice.php sql injection2025-08-21
CVE-2025-9305 — Injection | cvebase