CVE-2025-1956: code-projects Shopping Portal Login index.php sql injection
A vulnerability classified as critical has been found in code-projects Shopping Portal 1.0. This affects an unknown part of the file /Shopping/Admin/index.php of the component Login. The manipulation of the argument password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1956?
CVE-2025-1956 is classified as a critical vulnerability.
How does CVE-2025-1956 exploit occur?
CVE-2025-1956 exploits occur through SQL injection via manipulated login credentials.
What component is affected by CVE-2025-1956?
CVE-2025-1956 affects the login component of the Admin panel in Shopping Portal 1.0.
How can I mitigate CVE-2025-1956?
Mitigation of CVE-2025-1956 involves sanitizing user inputs and employing prepared statements in SQL queries.
Which software is impacted by CVE-2025-1956?
CVE-2025-1956 impacts the Shopping Portal by code-projects.