CVE-2025-4250: code-projects Nero Social Networking Site index.php sql injection
A vulnerability was found in code-projects Nero Social Networking Site 1.0. It has been classified as critical. This affects an unknown part of the file /index.php. The manipulation of the argument fname/lname/login/password2/cpassword/address/cnumber/email/gender/propic/month leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4250?
CVE-2025-4250 is classified as critical due to its potential impact on the Nero Social Networking Site.
What part of Nero Social Networking Site is affected by CVE-2025-4250?
CVE-2025-4250 specifically affects a part of the file /index.php.
What kind of manipulation is possible with CVE-2025-4250?
CVE-2025-4250 allows for manipulation of multiple arguments including fname, lname, login, password2, cpassword, address, cnumber, email, gender, propic, and month.
How do I fix CVE-2025-4250?
To fix CVE-2025-4250, ensure that proper input validation and sanitization are implemented for the affected parameters in the application.
Which version of Nero Social Networking Site is affected by CVE-2025-4250?
CVE-2025-4250 affects Nero Social Networking Site version 1.0.