CVE-2025-0205: code-projects Online Shoe Store details2.php sql injection
Published Jan 4, 2025
·Updated
A vulnerability classified as critical has been found in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /details2.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Code-projects Online Shoe Store
Code-projects Online Shoe Store=1.0
Event History
Jan 4, 2025
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-0205?
CVE-2025-0205 is classified as a critical vulnerability.
2
How does CVE-2025-0205 affect the Online Shoe Store application?
CVE-2025-0205 allows for SQL injection through the manipulation of the 'id' argument in the /details2.php file.
3
Can CVE-2025-0205 be exploited remotely?
Yes, CVE-2025-0205 is exploitable remotely.
4
What versions of the Online Shoe Store are affected by CVE-2025-0205?
CVE-2025-0205 affects version 1.0 of the code-projects Online Shoe Store.
5
What should be done to mitigate the risk of CVE-2025-0205?
To mitigate CVE-2025-0205, it is recommended to sanitize user inputs in the application to prevent SQL injection.