CVE-2025-13280: CodeAstro Simple Inventory System Login index.php sql injection
A vulnerability was determined in CodeAstro Simple Inventory System 1.0. The impacted element is an unknown function of the file /index.php of the component Login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13280?
CVE-2025-13280 has been rated as a critical severity vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-13280?
To fix CVE-2025-13280, validate and sanitize user inputs, specifically the Username argument, to prevent SQL injection.
What component is affected by CVE-2025-13280?
CVE-2025-13280 affects the Login component of the CodeAstro Simple Inventory System located in the /index.php file.
Can CVE-2025-13280 be exploited remotely?
Yes, CVE-2025-13280 can be exploited remotely by manipulating the Username argument.
What type of vulnerability is CVE-2025-13280?
CVE-2025-13280 is classified as an SQL injection vulnerability.