SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters district_id , division_id, region_id, and ward_id.
CVE-2025-69946
Score 9.8 from GitHub Security Advisory (severity: CRITICAL) published 2026-07-31. CISA-ADP (Vulnrichment) CVSS v3.1 baseline 9.8; sources differ by 0.0.
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 9.8
- EG Score
- 9.8(high)
- EG Risk
- 75(Attend)EG Risk 75/100SSVC: Attend
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity98% × 45%Exploitation40% × 40%Automatability100% × 15%Action: Remediate soon — notable exploitation risk. - EPSS PROB
- 0%
- EPSS %ILE
- 27%
- KEV
- Not listed
Published
July 31, 2026
Last Modified
August 3, 2026
Advisory Details (6)
Auto-updated Aug 17, 2026TaintRadar/sql_injection_cves/loansystem/20250811-modern-loan-management-system-ajaxdata.php-district_id-sqli/20250811-modern-loan-management-system-ajaxdata.php-district_id-sqli.md at main · um-dsp/TaintRadar · GitHub
https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/loansystem/20250811-modern-loan-management-system-ajaxdata.php-district_id-sqli/20250811-modern-loan-management-system-ajaxdata.php-district_id-sqli.mdTaintRadar/sql_injection_cves/loansystem/20250811-modern-loan-management-system-delete_group.php-id-sqli/20250811-modern-loan-management-system-delete_group.php-id-sqli.md at main · um-dsp/TaintRadar · GitHub
https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/loansystem/20250811-modern-loan-management-system-delete_group.php-id-sqli/20250811-modern-loan-management-system-delete_group.php-id-sqli.mdTaintRadar/sql_injection_cves/loansystem/20250811-modern-loan-management-system-ajaxdata.php-ward_id-sqli/20250811-modern-loan-management-system-ajaxdata.php-ward_id-sqli.md at main · um-dsp/TaintRadar · GitHub
https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/loansystem/20250811-modern-loan-management-system-ajaxdata.php-ward_id-sqli/20250811-modern-loan-management-system-ajaxdata.php-ward_id-sqli.mdTaintRadar/sql_injection_cves/loansystem/20250811-modern-loan-management-system-ajaxdata.php-region_id-sqli/20250811-modern-loan-management-system-ajaxdata.php-region_id-sqli.md at main · um-dsp/TaintRadar · GitHub
https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/loansystem/20250811-modern-loan-management-system-ajaxdata.php-region_id-sqli/20250811-modern-loan-management-system-ajaxdata.php-region_id-sqli.mdTaintRadar/sql_injection_cves/loansystem/20250811-modern-loan-management-system-ajaxdata.php-division_id-sqli/20250811-modern-loan-management-system-ajaxdata.php-division_id-sqli.md at main · um-dsp/TaintRadar · GitHub
https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/loansystem/20250811-modern-loan-management-system-ajaxdata.php-division_id-sqli/20250811-modern-loan-management-system-ajaxdata.php-division_id-sqli.mdGitHub - um-dsp/TaintRadar: Multi-Language Code Property Graph-Based Vulnerability Analysis · GitHub
https://github.com/um-dsp/TaintRadarVendor Advisories for CVE-2025-69946(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 53× in last 7d / 144× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 144 total refreshes for this CVE.
- 2026-08-21 07:17 UTCGHSA enrichment
- 2026-08-21 03:03 UTCEG score recompute
- 2026-08-21 03:03 UTCGHSA enrichment
- 2026-08-20 22:55 UTCEPSS rescore
- 2026-08-20 22:49 UTCGHSA enrichment
- 2026-08-20 18:36 UTCGHSA enrichment
- 2026-08-20 14:23 UTCGHSA enrichment
- 2026-08-20 09:21 UTCGHSA enrichment
- 2026-08-20 05:08 UTCGHSA enrichment
- 2026-08-20 00:55 UTCGHSA enrichment
- 2026-08-19 20:33 UTCEG score recompute
- 2026-08-19 20:33 UTCGHSA enrichment
- 2026-08-19 17:03 UTCEPSS rescore
- 2026-08-19 16:19 UTCGHSA enrichment
- 2026-08-19 11:52 UTCGHSA enrichment
- 2026-08-19 07:38 UTCGHSA enrichment
- 2026-08-19 03:25 UTCGHSA enrichment
- 2026-08-18 22:48 UTCGHSA enrichment
- 2026-08-18 18:27 UTCEG score recompute
- 2026-08-18 18:27 UTCGHSA enrichment
- 2026-08-18 13:48 UTCEPSS rescore
- 2026-08-18 13:02 UTCGHSA enrichment
- 2026-08-18 08:42 UTCGHSA enrichment
- 2026-08-18 04:12 UTCGHSA enrichment
- 2026-08-17 23:56 UTCGHSA enrichment
Show 75 moreShow fewer
- 2026-08-17 19:42 UTCGHSA enrichment
- 2026-08-17 14:12 UTCEG score recompute
- 2026-08-17 14:12 UTCGHSA enrichment
- 2026-08-17 13:46 UTCEPSS rescore
- 2026-08-17 09:59 UTCGHSA enrichment
- 2026-08-17 05:46 UTCGHSA enrichment
- 2026-08-17 01:08 UTCGHSA enrichment
- 2026-08-16 20:55 UTCGHSA enrichment
- 2026-08-16 16:41 UTCEG score recompute
- 2026-08-16 16:41 UTCGHSA enrichment
- 2026-08-16 14:55 UTCEPSS rescore
- 2026-08-16 12:28 UTCGHSA enrichment
- 2026-08-16 08:15 UTCGHSA enrichment
- 2026-08-16 04:02 UTCEG score recompute
- 2026-08-16 04:02 UTCGHSA enrichment
- 2026-08-16 02:14 UTCEPSS rescore
- 2026-08-15 23:49 UTCGHSA enrichment
- 2026-08-15 19:36 UTCGHSA enrichment
- 2026-08-15 15:23 UTCGHSA enrichment
- 2026-08-15 11:10 UTCGHSA enrichment
- 2026-08-15 06:57 UTCGHSA enrichment
- 2026-08-15 02:38 UTCEG score recompute
- 2026-08-15 02:38 UTCGHSA enrichment
- 2026-08-15 01:30 UTCEPSS rescore
- 2026-08-14 22:24 UTCGHSA enrichment
- 2026-08-14 18:10 UTCGHSA enrichment
- 2026-08-14 13:57 UTCGHSA enrichment
- 2026-08-14 09:44 UTCGHSA enrichment
- 2026-08-14 05:31 UTCGHSA enrichment
- 2026-08-14 01:18 UTCEG score recompute
- 2026-08-14 01:18 UTCGHSA enrichment
- 2026-08-13 22:00 UTCEPSS rescore
- 2026-08-13 21:05 UTCGHSA enrichment
- 2026-08-13 16:47 UTCGHSA enrichment
- 2026-08-13 12:34 UTCGHSA enrichment
- 2026-08-13 08:21 UTCGHSA enrichment
- 2026-08-13 04:08 UTCGHSA enrichment
- 2026-08-12 23:55 UTCGHSA enrichment
- 2026-08-12 19:42 UTCGHSA enrichment
- 2026-08-12 15:29 UTCEG score recompute
- 2026-08-12 15:29 UTCGHSA enrichment
- 2026-08-12 13:50 UTCEPSS rescore
- 2026-08-12 11:11 UTCGHSA enrichment
- 2026-08-12 06:57 UTCGHSA enrichment
- 2026-08-12 02:44 UTCGHSA enrichment
- 2026-08-11 22:30 UTCGHSA enrichment
- 2026-08-11 18:17 UTCGHSA enrichment
- 2026-08-11 13:49 UTCEG score recompute
- 2026-08-11 13:49 UTCGHSA enrichment
- 2026-08-11 13:42 UTCEPSS rescore
- 2026-08-11 09:35 UTCGHSA enrichment
- 2026-08-11 05:22 UTCGHSA enrichment
- 2026-08-11 01:09 UTCEG score recompute
- 2026-08-11 01:09 UTCGHSA enrichment
- 2026-08-10 23:59 UTCEPSS rescore
- 2026-08-10 20:56 UTCGHSA enrichment
- 2026-08-10 16:42 UTCGHSA enrichment
- 2026-08-10 12:28 UTCGHSA enrichment
- 2026-08-10 08:11 UTCGHSA enrichment
- 2026-08-10 03:58 UTCGHSA enrichment
- 2026-08-09 23:45 UTCGHSA enrichment
- 2026-08-09 19:32 UTCGHSA enrichment
- 2026-08-09 15:19 UTCEG score recompute
- 2026-08-09 15:19 UTCGHSA enrichment
- 2026-08-09 13:46 UTCEPSS rescore
- 2026-08-09 11:06 UTCGHSA enrichment
- 2026-08-09 06:52 UTCGHSA enrichment
- 2026-08-09 02:39 UTCGHSA enrichment
- 2026-08-08 22:26 UTCGHSA enrichment
- 2026-08-08 18:13 UTCEG score recompute
- 2026-08-08 18:13 UTCGHSA enrichment
- 2026-08-08 16:36 UTCEPSS rescore
- 2026-08-08 14:00 UTCGHSA enrichment
- 2026-08-08 09:46 UTCGHSA enrichment
- 2026-08-08 05:33 UTCGHSA enrichment
Related CVEs(same CWE)
Frequently asked(5)
What is CVE-2025-69946?
When was CVE-2025-69946 disclosed?
Is CVE-2025-69946 actively exploited?
What is the CVSS score of CVE-2025-69946?
How do I remediate CVE-2025-69946?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2025-69946
Is Your Infrastructure Affected by CVE-2025-69946?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.