CVE-2025-15407: code-projects Online Guitar Store Create_category.php sql injection
A vulnerability has been found in code-projects Online Guitar Store 1.0. This impacts an unknown function of the file /admin/Createcategory.php. Such manipulation of the argument dreCtitle leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15407?
CVE-2025-15407 is classified as a critical SQL injection vulnerability.
How does CVE-2025-15407 exploit work?
CVE-2025-15407 exploits an SQL injection flaw in the /admin/Create_category.php file through manipulation of the dre_Ctitle argument.
What software is affected by CVE-2025-15407?
CVE-2025-15407 affects the Code-projects Online Guitar Store version 1.0.
Is remote execution possible with CVE-2025-15407?
Yes, CVE-2025-15407 allows for remote execution of the SQL injection attack.
How do I mitigate CVE-2025-15407?
Mitigation for CVE-2025-15407 involves validating and sanitizing user inputs in the affected application.