CVE-2025-15409: code-projects Online Guitar Store Delete_product.php sql injection
A vulnerability was determined in code-projects Online Guitar Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/Deleteproduct.php. Executing a manipulation of the argument delpro can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15409?
CVE-2025-15409 has a high severity due to the potential for SQL injection attacks.
How do I fix CVE-2025-15409?
To fix CVE-2025-15409, sanitize and validate user inputs in the /admin/Delete_product.php file to prevent SQL injection.
What product is affected by CVE-2025-15409?
CVE-2025-15409 affects the code-projects Online Guitar Store version 1.0.
Can CVE-2025-15409 be exploited remotely?
Yes, CVE-2025-15409 can be exploited remotely by manipulating the del_pro argument.
What kind of attack is possible with CVE-2025-15409?
CVE-2025-15409 can lead to SQL injection attacks, allowing unauthorized access to the database.