CVE-2025-3817: SourceCodester Online Eyewear Shop Master.php sql injection
A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file /oews/classes/Master.php?f=deletestock. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3817?
CVE-2025-3817 has been classified as a critical vulnerability.
What type of vulnerability is CVE-2025-3817?
CVE-2025-3817 is an SQL injection vulnerability affecting the SourceCodester Online Eyewear Shop.
How does CVE-2025-3817 affect the application?
CVE-2025-3817 allows attackers to manipulate the argument ID in a specific file, leading to unauthorized database access.
How do I fix CVE-2025-3817?
To fix CVE-2025-3817, ensure proper input validation and parameterized queries are implemented in the affected code.
Which software version is affected by CVE-2025-3817?
CVE-2025-3817 affects SourceCodester Online Eyewear Shop version 1.0.