A vulnerability identified as critical has been detected in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/add_invoice.php. Performing manipulation of the argument ServiceId results in sql injection.

This vulnerability is known as CVE-2025-11615. Remote exploitation of the attack is possible. Furthermore, an exploit is available.