CVE-2025-13575: code-projects Blog Site Category blog.php category_exists sql injection
A security vulnerability has been detected in code-projects Blog Site 1.0. Impacted is the function categoryexists of the file /resources/functions/blog.php of the component Category Handler. Such manipulation of the argument name/field leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Multiple endpoints are affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13575?
CVE-2025-13575 is categorized as a high-severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2025-13575?
To fix CVE-2025-13575, you should sanitize and validate user inputs in the category_exists function to prevent SQL injection.
Which software is affected by CVE-2025-13575?
CVE-2025-13575 impacts Code-projects Blog Site version 1.0, specifically the Category Handler component.
What type of vulnerability is CVE-2025-13575?
CVE-2025-13575 is an SQL injection vulnerability that can allow attackers to manipulate database queries.
Can CVE-2025-13575 be exploited remotely?
Yes, CVE-2025-13575 can be exploited remotely if an attacker can access the vulnerable user input field.