CVE-2025-6471: code-projects Online Bidding System administrator sql injection
A vulnerability classified as critical was found in code-projects Online Bidding System 1.0. Affected by this vulnerability is an unknown functionality of the file /administrator. The manipulation of the argument aduser leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6471?
CVE-2025-6471 is classified as a critical vulnerability due to its potential for remote SQL injection attacks.
How does CVE-2025-6471 affect the Online Bidding System?
CVE-2025-6471 affects the Online Bidding System by allowing remote attackers to manipulate the 'aduser' argument, leading to SQL injection.
Can CVE-2025-6471 be exploited remotely?
Yes, CVE-2025-6471 can be exploited remotely by attackers targeting the vulnerable file in the administrator panel.
How do I fix CVE-2025-6471 in my application?
To fix CVE-2025-6471, immediately sanitize and validate user inputs in the affected functionalities to mitigate SQL injection risks.
Is there a patch available for CVE-2025-6471?
As of now, specific patches for CVE-2025-6471 have not been released, so it is recommended to apply security best practices while awaiting updates.