CVE-2025-6317: code-projects Online Shoe Store confirm.php sql injection
A vulnerability classified as critical has been found in code-projects Online Shoe Store 1.0. This affects an unknown part of the file /admin/confirm.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6317?
CVE-2025-6317 is classified as critical due to its potential to allow remote SQL injection attacks.
How does CVE-2025-6317 affect the Online Shoe Store?
CVE-2025-6317 affects the Online Shoe Store's /admin/confirm.php file, allowing manipulation of the argument ID to perform SQL injection.
Who is affected by CVE-2025-6317?
Any instance of the Online Shoe Store version 1.0 is affected by CVE-2025-6317.
How can I remediate CVE-2025-6317?
To remediate CVE-2025-6317, ensure input validation and use prepared statements to prevent SQL injection in your application.
Can CVE-2025-6317 be exploited remotely?
Yes, CVE-2025-6317 can be exploited remotely, making it critical to address promptly.