First published: Fri Jan 03 2025(Updated: )
A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been classified as critical. This affects an unknown part of the file /user/search_result2.php of the component Parameter Handler. The manipulation of the argument search leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Code-projects Point of Sales and Inventory Management System | ||
Code-projects Point of Sales and Inventory Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0174 has been classified as critical due to its potential impact on the affected component.
To fix CVE-2025-0174, ensure that you sanitize and validate all input parameters in the /user/search_result2.php file.
CVE-2025-0174 affects the Parameter Handler functionality within the Point of Sales and Inventory Management System.
CVE-2025-0174 can lead to SQL injection attacks due to improper handling of user input.
As of now, a specific patch has not been released for CVE-2025-0174, so users should manually address the vulnerability.