CVE-2025-6840: code-projects Product Inventory System Login index.php sql injection
A vulnerability, which was classified as critical, was found in code-projects Product Inventory System 1.0. This affects an unknown part of the file /index.php of the component Login. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6840?
CVE-2025-6840 is classified as a critical severity vulnerability.
What type of vulnerability is CVE-2025-6840?
CVE-2025-6840 is a SQL injection vulnerability affecting the Login component in the Product Inventory System.
How do I fix CVE-2025-6840?
To fix CVE-2025-6840, sanitize and parameterize user inputs in the Login feature to prevent SQL injection.
Which software versions are affected by CVE-2025-6840?
CVE-2025-6840 affects version 1.0 of the Code-projects Product Inventory System.
What component of the software is impacted by CVE-2025-6840?
CVE-2025-6840 impacts the Login component found in the /index.php file.