First published: Tue Mar 04 2025(Updated: )
A vulnerability classified as critical has been found in code-projects Shopping Portal 1.0. This affects an unknown part of the file /Shopping/Admin/index.php of the component Login. The manipulation of the argument password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Code-projects Shopping Portal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1956 is classified as a critical vulnerability.
CVE-2025-1956 exploits occur through SQL injection via manipulated login credentials.
CVE-2025-1956 affects the login component of the Admin panel in Shopping Portal 1.0.
Mitigation of CVE-2025-1956 involves sanitizing user inputs and employing prepared statements in SQL queries.
CVE-2025-1956 impacts the Shopping Portal by code-projects.