CVE-2025-6668: code-projects Inventory Management System fetchSelectedBrand.php sql injection
A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. This affects an unknown part of the file /phpaction/fetchSelectedBrand.php. The manipulation of the argument brandId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6668?
CVE-2025-6668 has been classified as critical due to its potential for SQL injection.
How do I fix CVE-2025-6668?
To fix CVE-2025-6668, you should sanitize user inputs and use prepared statements to prevent SQL injection.
What component of the Inventory Management System is affected by CVE-2025-6668?
CVE-2025-6668 affects the /php_action/fetchSelectedBrand.php file in the Inventory Management System.
What risk does CVE-2025-6668 pose to users?
CVE-2025-6668 poses a risk of unauthorized access to the database and manipulation of sensitive data.
Which software is impacted by CVE-2025-6668?
CVE-2025-6668 impacts the Code-projects Inventory Management System version 1.0.