CVE-2025-6364: code-projects Simple Pizza Ordering System adduser-exec.php sql injection
A vulnerability has been found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /adduser-exec.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6364?
CVE-2025-6364 is classified as a critical vulnerability.
How do I fix CVE-2025-6364?
To fix CVE-2025-6364, you should validate and sanitize the input for the Username argument in the /adduser-exec.php file to prevent SQL injection.
What is the impact of CVE-2025-6364?
The impact of CVE-2025-6364 includes the potential for an attacker to execute arbitrary SQL queries on the database.
Which software is affected by CVE-2025-6364?
CVE-2025-6364 affects Code-projects Simple Pizza Ordering System version 1.0.
Can CVE-2025-6364 lead to data breaches?
Yes, CVE-2025-6364 can lead to data breaches due to SQL injection vulnerabilities that allow unauthorized access to sensitive data.