CVE-2025-6580CRITICAL 9.8EPSS p35.6%
CVE-2025-6580CVE-2025-6580
Description
A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the component Login. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.45% probability of exploitation · percentile 35.6% · 2026-06-19T12:03:05Z |
| Published | 2025-06-24 |
| Last modified | 2026-04-29 |
Underlying weaknesses· 2
References
- https://github.com/Colorado-all/cve/blob/main/Best%20salon%20management%20system/SQL-1.md
- https://vuldb.com/?ctiid.313776
- https://vuldb.com/?id.313776
- https://vuldb.com/?submit.601908
- https://www.sourcecodester.com/
- https://github.com/Colorado-all/cve/blob/main/Best%20salon%20management%20system/SQL-1.md
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-74 | 0% | live |
| Weakness | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')cwe-89 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.