CVE-2025-9150
Last modified
CVE-2025-9150 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. A vulnerability was identified in Surbowl dormitory-management-php up to 9f1d9d1f528cabffc66fda3652c56ff327fda317. Affected is an unknown function of the file /admin/violation_add.php?id=2. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
A vulnerability was identified in Surbowl dormitory-management-php up to 9f1d9d1f528cabffc66fda3652c56ff327fda317. Affected is an unknown function of the file /admin/violation_add.php?id=2. Such manipulation of the argument ID leads to sql injection. The attack may be performed from a remote location. The exploit is publicly available and might be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. This vulnerability only affects products that are no longer supported by the maintainer.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-9150?
How severe is CVE-2025-9150?
How do I fix CVE-2025-9150?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-9144A weakness has been identified in Scada-LTS 2.7.8.1. This vu…5.4
- CVE-2025-9145A security vulnerability has been detected in Scada-LTS 2.7.…5.4
- CVE-2025-9146A flaw has been found in Linksys E5600 1.1.0.26. The affecte…8.1
- CVE-2025-9147A vulnerability has been found in jasonclark getsemantic up …6.1
- CVE-2025-9148A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7…6.3
- CVE-2025-9149A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V…9.8
- CVE-2025-9151A security flaw has been discovered in LiuYuYang01 ThriveX-B…6.3
- CVE-2025-9152An improper privilege management vulnerability exists in WSO…9.8
- CVE-2025-9153A vulnerability was detected in itsourcecode Online Tour and…8.8
- CVE-2025-9154A flaw has been found in itsourcecode Online Tour and Travel…9.8
- CVE-2025-9155A vulnerability has been found in itsourcecode Online Tour a…9.8
- CVE-2025-9156A vulnerability was found in itsourcecode Sports Management …9.8
Are you affected by CVE-2025-9150?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
