CVE-2025-3296: SourceCodester Online Eyewear Shop Users.php sql injection
Published Apr 5, 2025
·Updated
A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=deletecustomer. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Sourcecodester Online Eyewear Shop
oretnom23 Online Eyewear Shop=1.0
Event History
Apr 5, 2025
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
DescriptionSeverityWeakness
Apr 5, 57247
Event
via FIRST·06:59 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-3296?
CVE-2025-3296 is classified as a critical vulnerability.
2
How do I fix CVE-2025-3296?
To fix CVE-2025-3296, implement input validation and sanitization on the ID parameter in the /classes/Users.php file.
3
What type of attack is associated with CVE-2025-3296?
CVE-2025-3296 is associated with SQL injection attacks.
4
Which application is affected by CVE-2025-3296?
CVE-2025-3296 affects the SourceCodester Online Eyewear Shop version 1.0.
5
What kind of processing issue does CVE-2025-3296 involve?
CVE-2025-3296 involves improper handling of the argument ID leading to SQL injection.