CVE-2025-6500: code-projects Inventory Management System editCategories.php sql injection
A vulnerability, which was classified as critical, has been found in code-projects Inventory Management System 1.0. Affected by this issue is some unknown functionality of the file /phpaction/editCategories.php. The manipulation of the argument editCategoriesName leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6500?
CVE-2025-6500 is classified as a critical vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2025-6500?
To fix CVE-2025-6500, sanitize and validate user inputs in the editCategoriesName argument to prevent SQL injection.
What software is affected by CVE-2025-6500?
CVE-2025-6500 affects version 1.0 of the code-projects Inventory Management System.
What kind of attack can be executed through CVE-2025-6500?
CVE-2025-6500 can be exploited to execute SQL injection attacks, allowing unauthorized access to the database.
Is CVE-2025-6500 being actively exploited?
While CVE-2025-6500 is critical and poses a significant risk, the extent of active exploitation is currently unknown.