CVE-2025-26157

A SQL Injection vulnerability was found in /bpms/index.php in Source Code and Project Beauty Parlour Management System V1.1, which allows remote attackers to execute arbitrary code via the name POST request parameter.
CVSS

No CVSS.

References
Link Resource
https://github.com/rtnthakur/CVE/blob/main/others/README.md Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:darkseid:beauty_parlour_management_system:1.1:*:*:*:*:*:*:*

History

06 Jun 2025, 17:58

Type Values Removed Values Added
CPE cpe:2.3:a:darkseid:beauty_parlour_management_system:1.1:*:*:*:*:*:*:*
References () https://github.com/rtnthakur/CVE/blob/main/others/README.md - () https://github.com/rtnthakur/CVE/blob/main/others/README.md - Exploit, Third Party Advisory
First Time Darkseid beauty Parlour Management System
Darkseid

14 Feb 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-14 17:15

Updated : 2025-06-06 17:58


NVD link : CVE-2025-26157

Mitre link : CVE-2025-26157


JSON object : View

Products Affected

darkseid

  • beauty_parlour_management_system
CWE

No CWE.