CVE-2025-6502: code-projects Inventory Management System changePassword.php sql injection
A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /phpaction/changePassword.php. The manipulation of the argument userid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6502?
CVE-2025-6502 is classified as a critical vulnerability.
What are the consequences of exploiting CVE-2025-6502?
Exploiting CVE-2025-6502 allows an attacker to perform SQL injection through the user_id argument.
How do I fix CVE-2025-6502?
To fix CVE-2025-6502, ensure that user input is properly sanitized and validated before being used in SQL queries.
What software is affected by CVE-2025-6502?
CVE-2025-6502 affects the code-projects Inventory Management System version 1.0.
Can CVE-2025-6502 be exploited remotely?
Yes, CVE-2025-6502 can be exploited remotely if an attacker has access to the vulnerable endpoint.