CVE-2025-15011: code-projects Simple Stock System logout.php sql injection
Published Dec 22, 2025
·Updated
A vulnerability was found in code-projects Simple Stock System 1.0. Impacted is an unknown function of the file /logout.php. The manipulation of the argument uname results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
Affected Software
2 affected components
Code-projects Simple Stock System
Carmelo Simple Stock System=1.0
Event History
Dec 22, 2025
CVE Published
via MITRE·03:32 AM
Data Sourced
via MITRE·03:32 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-15011?
CVE-2025-15011 is categorized as a high severity vulnerability due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2025-15011?
To fix CVE-2025-15011, users should sanitize and validate all inputs, particularly the 'uname' parameter in the /logout.php file.
3
What type of attack is possible with CVE-2025-15011?
CVE-2025-15011 allows for SQL injection attacks that can be executed remotely.
4
Which software is affected by CVE-2025-15011?
CVE-2025-15011 affects version 1.0 of the Simple Stock System by Code-projects.
5
Is there a public exploit available for CVE-2025-15011?
Yes, the exploit for CVE-2025-15011 has been made public.