CVE-2025-15410: code-projects Online Guitar Store login.php sql injection
A vulnerability was identified in code-projects Online Guitar Store 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Lemail leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15410?
CVE-2025-15410 is classified as a critical severity vulnerability due to its potential for remote SQL injection.
How do I fix CVE-2025-15410?
To mitigate CVE-2025-15410, sanitize user inputs on the /login.php file and implement prepared statements for database queries.
What software is affected by CVE-2025-15410?
CVE-2025-15410 affects Code-projects Online Guitar Store version 1.0.
Can CVE-2025-15410 be exploited remotely?
Yes, CVE-2025-15410 can be exploited remotely through the manipulation of the L_email argument.
What type of attack is associated with CVE-2025-15410?
CVE-2025-15410 is associated with SQL injection attacks.