CVE-2025-8235: code-projects Online Ordering System product.php sql injection
A vulnerability was found in code-projects Online Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/product.php. The manipulation of the argument Name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8235?
CVE-2025-8235 has been classified as critical due to its potential for SQL injection.
How do I fix CVE-2025-8235?
To fix CVE-2025-8235, you should implement proper input validation and prepared statements to mitigate SQL injection risks.
Which software is affected by CVE-2025-8235?
CVE-2025-8235 affects the code-projects Online Ordering System version 1.0.
Can CVE-2025-8235 be exploited remotely?
Yes, CVE-2025-8235 can be exploited remotely by manipulating the argument Name in the affected file.
What type of vulnerability is CVE-2025-8235?
CVE-2025-8235 is an SQL injection vulnerability that allows attackers to manipulate database queries.