CVE-2025-6361: code-projects Simple Pizza Ordering System adds.php sql injection
Published Jun 20, 2025
·Updated
A vulnerability classified as critical was found in code-projects Simple Pizza Ordering System 1.0. This vulnerability affects unknown code of the file /adds.php. The manipulation of the argument userid leads to sql injection. The attack can be initiated remotely.
Affected Software
2 affected components
Code-projects Simple Pizza Ordering System
Carmelo Simple Pizza Ordering System=1.0
Event History
Jun 20, 2025
CVE Published
via MITRE·07:31 PM
Data Sourced
via MITRE·07:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 15, 58473
Event
via NVD·08:29 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-6361?
CVE-2025-6361 is classified as a critical vulnerability.
2
What type of vulnerability is CVE-2025-6361?
CVE-2025-6361 is an SQL injection vulnerability affecting the Simple Pizza Ordering System.
3
How does CVE-2025-6361 impact the Simple Pizza Ordering System?
CVE-2025-6361 allows remote attackers to manipulate the argument userid and execute unauthorized SQL commands.
4
How do I fix CVE-2025-6361?
To fix CVE-2025-6361, validate and sanitize user input to prevent SQL injection in the /adds.php file.
5
Is CVE-2025-6361 exploitable remotely?
Yes, CVE-2025-6361 can be exploited remotely by attackers.