CVE-2025-14247: code-projects Simple Shopping Cart additems.php sql injection
A vulnerability was determined in code-projects Simple Shopping Cart 1.0. This issue affects some unknown processing of the file /Admin/additems.php. Executing manipulation of the argument itemname can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14247?
CVE-2025-14247 has a high severity rating due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-14247?
To fix CVE-2025-14247, sanitize and validate all user inputs in the /Admin/additems.php file to prevent SQL injection.
Who is affected by CVE-2025-14247?
CVE-2025-14247 affects users of the Simple Shopping Cart version 1.0 by code-projects.
What type of vulnerability is CVE-2025-14247?
CVE-2025-14247 is an SQL injection vulnerability that allows attackers to manipulate database queries.
Can CVE-2025-14247 be exploited remotely?
Yes, CVE-2025-14247 can be exploited remotely without requiring physical access to the affected system.