CVE-2025-8498: code-projects Online Medicine Guide index.php sql injection
A security vulnerability has been detected in code-projects Online Medicine Guide 1.0. This vulnerability affects unknown code of the file /cart/index.php. Such manipulation of the argument uname leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8498?
CVE-2025-8498 has been classified as critical due to its potential for SQL injection exploitation.
How do I fix CVE-2025-8498?
To fix CVE-2025-8498, ensure that input validation and parameterized queries are used in the /cart/index.php file.
What software is affected by CVE-2025-8498?
CVE-2025-8498 affects the Code-projects Online Medicine Guide version 1.0.
Can CVE-2025-8498 be exploited remotely?
Yes, CVE-2025-8498 can be exploited remotely, allowing attackers to initiate SQL injection attacks.
What part of the software does CVE-2025-8498 affect?
CVE-2025-8498 specifically affects the /cart/index.php file within the Online Medicine Guide application.