CVE-2025-6357: code-projects Simple Pizza Ordering System paymentportal.php sql injection
A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been classified as critical. Affected is an unknown function of the file /paymentportal.php. The manipulation of the argument person leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6357?
CVE-2025-6357 has been classified as a critical vulnerability.
What type of vulnerability is CVE-2025-6357?
CVE-2025-6357 is a SQL injection vulnerability found in the Simple Pizza Ordering System.
How does CVE-2025-6357 affect the Simple Pizza Ordering System?
CVE-2025-6357 allows remote attackers to manipulate the 'person' argument in /paymentportal.php, leading to SQL injection.
How can I fix CVE-2025-6357 in my installation?
To fix CVE-2025-6357, ensure that user input is properly sanitized and use prepared statements for database queries.
Is there a known exploit for CVE-2025-6357?
Yes, exploit details for CVE-2025-6357 indicate that it can be exploited remotely.