CVE-2025-6360: code-projects Simple Pizza Ordering System portal.php sql injection
A vulnerability classified as critical has been found in code-projects Simple Pizza Ordering System 1.0. This affects an unknown part of the file /portal.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6360?
CVE-2025-6360 is classified as a critical vulnerability due to the potential for SQL injection.
How does CVE-2025-6360 affect the Simple Pizza Ordering System?
CVE-2025-6360 affects the Simple Pizza Ordering System by allowing remote attackers to manipulate the ID argument leading to SQL injection.
How do I fix CVE-2025-6360?
To fix CVE-2025-6360, you should sanitize and validate all user inputs, especially the ID parameter in the /portal.php file.
Can CVE-2025-6360 be exploited remotely?
Yes, CVE-2025-6360 can be exploited remotely, allowing attackers to execute SQL injection attacks from outside the application.
What components of Simple Pizza Ordering System are impacted by CVE-2025-6360?
CVE-2025-6360 specifically impacts the /portal.php file in the Simple Pizza Ordering System.