First published: Tue May 06 2025(Updated: )
A vulnerability, which was classified as critical, was found in SourceCodester Advanced Web Store 1.0. Affected is an unknown function of the file /admin/admin_addnew_product.php. The manipulation of the argument txtProdId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
SourceCodester Advanced Web Store |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4313 is classified as a critical vulnerability.
To fix CVE-2025-4313, sanitize user inputs and use prepared statements to prevent SQL injection.
CVE-2025-4313 affects SourceCodester Advanced Web Store version 1.0.
CVE-2025-4313 is an SQL injection vulnerability.
The vulnerability in CVE-2025-4313 is found in the file /admin/admin_addnew_product.php.