CVE-2025-0173: SourceCodester Online Eyewear Shop view_order.php sql injection
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /orders/vieworder.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0173?
CVE-2025-0173 is classified as a critical vulnerability.
How do I fix CVE-2025-0173?
To fix CVE-2025-0173, sanitize and validate input parameters in the /orders/view_order.php file to prevent SQL injection.
What type of attack is associated with CVE-2025-0173?
CVE-2025-0173 is associated with SQL injection attacks that can be executed remotely.
Which software is affected by CVE-2025-0173?
CVE-2025-0173 affects the SourceCodester Online Eyewear Shop version 1.0.
What is the impact of CVE-2025-0173?
The impact of CVE-2025-0173 includes potential unauthorized access to the database through SQL injection.