A vulnerability was determined in SourceCodester Online Bank Management System up to 1.0. This vulnerability affects unknown code of the file /bank/transfer.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 21 Aug 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Oretnom23
Oretnom23 online Bank Management System
CPEs cpe:2.3:a:oretnom23:online_bank_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Oretnom23
Oretnom23 online Bank Management System

Sat, 16 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester online Bank Management System
Vendors & Products Sourcecodester
Sourcecodester online Bank Management System

Fri, 15 Aug 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 15 Aug 2025 08:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in SourceCodester Online Bank Management System up to 1.0. This vulnerability affects unknown code of the file /bank/transfer.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely.
Title SourceCodester Online Bank Management System transfer.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-08-15T16:33:13.921Z

Reserved: 2025-08-14T07:04:07.311Z

Link: CVE-2025-9021

cve-icon Vulnrichment

Updated: 2025-08-15T16:33:08.710Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-15T08:15:27.973

Modified: 2025-08-21T16:21:28.687

Link: CVE-2025-9021

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-16T21:40:55Z