CVE-2025-7125
Last modified
CVE-2025-7125 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. A vulnerability classified as critical was found in itsourcecode Employee Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/editempeducation.php. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
A vulnerability classified as critical was found in itsourcecode Employee Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/editempeducation.php. The manipulation of the argument coursepg leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Clivedelacruz | Employee Management System | 1.0 |
References
- https://github.com/manyufann/CVE/issues/1Exploit, Third Party Advisory
- https://itsourcecode.com/Product
- https://vuldb.com/?ctiid.315037Permissions Required
- https://vuldb.com/?id.315037Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.605933Third Party Advisory, VDB Entry
- https://github.com/manyufann/CVE/issues/1Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-7125?
How severe is CVE-2025-7125?
How do I fix CVE-2025-7125?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-71244SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the …6.1
- CVE-2025-71245Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-71246Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-71247Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-71248Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-71249Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-71250Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-71251In IMS, there is a possible system crash due to improper inp…7.5
- CVE-2025-71252In Modem IMS, there is a possible improper input validation.…7.5
- CVE-2025-71253In Modem IMS, there is a possible improper input validation.…7.5
- CVE-2025-71254In Modem IMS, there is a possible improper input validation.…7.5
- CVE-2025-71255In Modem IMS, there is a possible improper input validation.…7.5
Are you affected by CVE-2025-7125?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
