A SQL injection vulnerability was found in the '/cts/admin/?page=zone' file of ITSourcecode COVID Tracking System Using QR-Code v1.0. The reason for this issue is that attackers inject malicious code from the parameter 'id' and use it directly in SQL queries without the need for appropriate cleaning or validation.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 03 Jan 2026 03:00:00 +0900

Type Values Removed Values Added
First Time appeared Angeljudesuarez
Angeljudesuarez covid Tracking System Using Qr-code
CPEs cpe:2.3:a:angeljudesuarez:covid_tracking_system_using_qr-code:1.0:*:*:*:*:*:*:*
Vendors & Products Angeljudesuarez
Angeljudesuarez covid Tracking System Using Qr-code

Fri, 19 Dec 2025 09:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 19:00:00 +0900

Type Values Removed Values Added
First Time appeared Itsourcecode
Itsourcecode covid Tracking System
Vendors & Products Itsourcecode
Itsourcecode covid Tracking System

Thu, 18 Dec 2025 02:30:00 +0900

Type Values Removed Values Added
Weaknesses CWE-89
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Thu, 18 Dec 2025 01:30:00 +0900

Type Values Removed Values Added
Description A SQL injection vulnerability was found in the '/cts/admin/?page=zone' file of ITSourcecode COVID Tracking System Using QR-Code v1.0. The reason for this issue is that attackers inject malicious code from the parameter 'id' and use it directly in SQL queries without the need for appropriate cleaning or validation.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-12-17T16:43:42.257Z

Reserved: 2025-12-08T00:00:00.000Z

Link: CVE-2025-67285

cve-icon Vulnrichment

Updated: 2025-12-17T16:43:01.688Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-17T17:15:51.137

Modified: 2026-01-02T17:46:53.753

Link: CVE-2025-67285

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-18T18:57:33Z

Weaknesses