A vulnerability, which was classified as critical, was found in SourceCodester Survey Application System 1.0. This impacts the function save_user/update_user of the file /LoginRegistration.php. Executing manipulation of the argument fullname can lead to sql injection.

This vulnerability appears as CVE-2025-12929. The attack may be performed from remote. In addition, an exploit is available.

Other parameters might be affected as well.