CVE-2025-11603: code-projects Simple Food Ordering System editproduct.php sql injection
A vulnerability was found in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of the file /editproduct.php. The manipulation of the argument Category results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11603?
CVE-2025-11603 is classified as a high severity vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-11603?
To fix CVE-2025-11603, sanitize and validate user inputs in the /editproduct.php file to prevent SQL injection.
What systems are affected by CVE-2025-11603?
CVE-2025-11603 affects version 1.0 of the Simple Food Ordering System by Code-projects.
Can CVE-2025-11603 be exploited remotely?
Yes, CVE-2025-11603 can be exploited remotely by manipulating the Category argument.
What is SQL injection in the context of CVE-2025-11603?
In the context of CVE-2025-11603, SQL injection refers to the attack that exploits vulnerabilities in the application's code to manipulate SQL queries executed by the database.