Review reviewHigh
CVE-2025-67405
the affected product
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password.
- CVSS
- 7.3
- EPSS
- 0.17% 6.53% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.30