---
id: CVE-2025-12929
title: A flaw has been found in SourceCodester Survey Application System 1.0
summary: >-
  A flaw has been found in SourceCodester Survey Application System 1.0. This
  impacts the function save_user/update_user of the file /LoginRegistration.php.
  Executing manipulation of the argument fullname can lead to sql injection. The
  att…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
  - CWE-89
vendor: oretnom23
product: survey_application_system
affected:
  - survey_application_system = 1.0
published: '2025-11-10'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12929'
references:
  - url: >-
      https://github.com/lakshayyverma/CVE-Discovery/blob/main/Survey%20Application%20System.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.331649'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.331649'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.681746'
    label: cna@vuldb.com
  - url: 'https://www.sourcecodester.com/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/lakshayyverma/CVE-Discovery/blob/main/Survey%20Application%20System.md
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00441
epssPercentile: 0.36243
ingestedAt: '2026-10-07T21:54:14.999Z'
---

## Overview

A flaw has been found in SourceCodester Survey Application System 1.0. This impacts the function save_user/update_user of the file /LoginRegistration.php. Executing manipulation of the argument fullname can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. Other parameters might be affected as well.

## Affected

- `survey_application_system = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
