CVE-2025-6306: code-projects Online Shoe Store admin_index.php sql injection
A vulnerability was found in code-projects Online Shoe Store 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/adminindex.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6306?
CVE-2025-6306 has been declared as critical due to its potential for SQL injection vulnerabilities.
How do I fix CVE-2025-6306?
To fix CVE-2025-6306, it is recommended to sanitize and validate all user inputs in the /admin/admin_index.php file.
What systems are affected by CVE-2025-6306?
CVE-2025-6306 affects the Online Shoe Store version 1.0 developed by Code-projects.
Can CVE-2025-6306 be exploited remotely?
Yes, CVE-2025-6306 can be exploited remotely through SQL injection by manipulating the Username argument.
What type of vulnerability is CVE-2025-6306?
CVE-2025-6306 is classified as an SQL injection vulnerability that can compromise the database integrity.