CVE-2025-4312: SourceCodester Advanced Web Store productdetail.php sql injection
A vulnerability, which was classified as critical, has been found in SourceCodester Advanced Web Store 1.0. This issue affects some unknown processing of the file /productdetail.php. The manipulation of the argument prodid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4312?
CVE-2025-4312 is classified as a critical vulnerability.
What type of vulnerability is CVE-2025-4312?
CVE-2025-4312 is an SQL injection vulnerability that affects the /productdetail.php file.
How can I identify if my system is affected by CVE-2025-4312?
You can identify if your system is affected by checking if the SourceCodester Advanced Web Store 1.0 is in use and reviewing any input validation on the prodid parameter.
How do I fix CVE-2025-4312?
To fix CVE-2025-4312, validate and sanitize user input for the prodid parameter to prevent SQL injection.
Can CVE-2025-4312 be exploited remotely?
Yes, CVE-2025-4312 can be exploited remotely by manipulating the prodid argument.