CVE-2025-0207: code-projects Online Shoe Store login.php sql injection
Published Jan 4, 2025
·Updated
A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /function/login.php. The manipulation of the argument password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Code-projects Online Shoe Store=1.0
Event History
Jan 4, 2025
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
DescriptionSeverityWeakness
Oct 12, 57005
Event
via FIRST·08:40 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-0207?
CVE-2025-0207 is classified as a critical vulnerability.
2
How do I fix CVE-2025-0207?
To fix CVE-2025-0207, sanitize inputs and use prepared statements to prevent SQL injection in the /function/login.php file.
3
What type of vulnerability is CVE-2025-0207?
CVE-2025-0207 is an SQL injection vulnerability.
4
Which version of Online Shoe Store is affected by CVE-2025-0207?
The affected version of Online Shoe Store is 1.0.
5
What are the potential impacts of CVE-2025-0207?
CVE-2025-0207 could allow attackers to manipulate database queries, potentially leading to data breaches.