CVE-2025-6902: code-projects Inventory Management System editUser.php sql injection
A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /phpaction/editUser.php. The manipulation of the argument edituserName leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6902?
CVE-2025-6902 has been classified as critical.
How do I fix CVE-2025-6902?
To fix CVE-2025-6902, validate and sanitize inputs to prevent SQL injection in the editUser.php file.
What software is affected by CVE-2025-6902?
CVE-2025-6902 affects the Code-projects Inventory Management System version 1.0.
What type of attack can be performed due to CVE-2025-6902?
CVE-2025-6902 allows for SQL injection attacks through the manipulation of the edituserName argument.
Where does CVE-2025-6902 occur in the code?
CVE-2025-6902 occurs in an unspecified function of the file /php_action/editUser.php.