A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /panel/search-appointment.php. The manipulation of the argument searchdata leads to sql injection.

This vulnerability was named CVE-2025-6878. The attack can be initiated remotely. Furthermore, there is an exploit available.