CVE-2025-6303: code-projects Online Shoe Store contactus1.php sql injection
A vulnerability has been found in code-projects Online Shoe Store 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /contactus1.php. The manipulation of the argument Message leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6303?
The severity of CVE-2025-6303 is classified as critical due to its potential for remote SQL injection.
How do I fix CVE-2025-6303?
To fix CVE-2025-6303, sanitize all user inputs in the /contactus1.php file to prevent SQL injection attacks.
What are the potential impacts of exploiting CVE-2025-6303?
Exploiting CVE-2025-6303 could allow an attacker to execute arbitrary SQL commands on the database.
Which applications are affected by CVE-2025-6303?
CVE-2025-6303 affects code-projects Online Shoe Store version 1.0.
Can CVE-2025-6303 be exploited remotely?
Yes, CVE-2025-6303 can be exploited remotely due to its nature of SQL injection through the vulnerable file.