CVE-2025-1903: Codezips Online Shopping Website cart_add.php sql injection
A vulnerability was found in Codezips Online Shopping Website 1.0. It has been rated as critical. This issue affects some unknown processing of the file /cartadd.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1903?
CVE-2025-1903 has been rated as critical due to its potential for SQL injection vulnerabilities.
How does CVE-2025-1903 affect the Codezips Online Shopping Website?
CVE-2025-1903 affects the processing of the file /cart_add.php, allowing for remote SQL injection attacks.
What kind of attacks can be executed using CVE-2025-1903?
CVE-2025-1903 allows attackers to initiate SQL injection attacks remotely through manipulated arguments.
How can I mitigate the risk associated with CVE-2025-1903?
To mitigate the risk of CVE-2025-1903, ensure proper input validation and sanitization in the affected file /cart_add.php.
Is it necessary to update the Codezips Online Shopping Website to address CVE-2025-1903?
Yes, it is essential to apply security patches or updates to the Codezips Online Shopping Website to fix the vulnerabilities presented by CVE-2025-1903.