CVE-2025-6665: code-projects Inventory Management System editBrand.php sql injection
A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /phpaction/editBrand.php. The manipulation of the argument editBrandStatus leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6665?
CVE-2025-6665 is classified as a critical vulnerability.
How does CVE-2025-6665 affect the Inventory Management System?
CVE-2025-6665 enables SQL injection through manipulation of the editBrandStatus argument in the /php_action/editBrand.php file.
How can I mitigate CVE-2025-6665?
To mitigate CVE-2025-6665, sanitize and validate inputs before processing them in the application.
What are the potential impacts of CVE-2025-6665?
CVE-2025-6665 can lead to unauthorized database access and manipulation of sensitive data.
Is a patch available for CVE-2025-6665?
As of now, there has been no public announcement regarding a patch for CVE-2025-6665.