CVE-2025-6821: code-projects Inventory Management System createOrder.php sql injection
A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. This affects an unknown part of the file /phpaction/createOrder.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6821?
The severity of CVE-2025-6821 is classified as critical.
How does CVE-2025-6821 allow for exploitation?
CVE-2025-6821 allows for exploitation through SQL injection via the /php_action/createOrder.php file.
Can CVE-2025-6821 be exploited remotely?
Yes, CVE-2025-6821 can be exploited remotely.
What parts of the Inventory Management System are affected by CVE-2025-6821?
CVE-2025-6821 affects an unknown part of the Inventory Management System related to the order creation functionality.
How do I mitigate the risk of CVE-2025-6821?
To mitigate the risk of CVE-2025-6821, ensure to sanitize and validate all user inputs to prevent SQL injection.