CVE-2025-6891: code-projects Inventory Management System createUser.php sql injection
A vulnerability classified as critical has been found in code-projects Inventory Management System 1.0. Affected is an unknown function of the file /phpaction/createUser.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6891?
CVE-2025-6891 is classified as a critical vulnerability due to its potential to allow remote SQL injection attacks.
How do I fix CVE-2025-6891?
To fix CVE-2025-6891, validate and sanitize input passed to the Username argument in /php_action/createUser.php to prevent SQL injection.
What impact does CVE-2025-6891 have on my system?
CVE-2025-6891 can allow attackers to execute arbitrary SQL commands, potentially compromising the database and its data.
Is my version of Inventory Management System vulnerable to CVE-2025-6891?
If you are using Inventory Management System version 1.0, your system is vulnerable to CVE-2025-6891.
Who is affected by CVE-2025-6891?
Any user or organization utilizing code-projects Inventory Management System 1.0 is affected by CVE-2025-6891.