CVE-2025-0564: code-projects Fantasy-Cricket authenticate.php sql injection
A vulnerability was found in code-projects Fantasy-Cricket 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /authenticate.php. The manipulation of the argument uname leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0564?
CVE-2025-0564 has been declared as critical due to its potential for remote SQL injection.
How do I fix CVE-2025-0564?
To fix CVE-2025-0564, implement prepared statements or parameterized queries to prevent SQL injection in the /authenticate.php file.
What type of attack can exploit CVE-2025-0564?
CVE-2025-0564 can be exploited through remote SQL injection attacks targeting the uname argument.
Which software is affected by CVE-2025-0564?
CVE-2025-0564 affects the Fantasy-Cricket application developed by code-projects.
Can CVE-2025-0564 be exploited remotely?
Yes, CVE-2025-0564 allows remote attackers to exploit SQL injection vulnerabilities.