CVE-2025-8936: 1000 Projects Sales Management System dordupdate.php sql injection
A vulnerability was determined in 1000 Projects Sales Management System 1.0. Affected by this issue is some unknown functionality of the file /superstore/dist/dordupdate.php. The manipulation of the argument select2 leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8936?
CVE-2025-8936 is considered a high severity vulnerability due to the potential for remote SQL injection.
How do I fix CVE-2025-8936?
To fix CVE-2025-8936, update the 1000 Projects Sales Management System to the latest version that addresses this SQL injection issue.
What type of vulnerability is CVE-2025-8936?
CVE-2025-8936 is an SQL injection vulnerability affecting the /superstore/dist/dordupdate.php file.
Can CVE-2025-8936 be exploited remotely?
Yes, CVE-2025-8936 can be exploited remotely, allowing attackers to manipulate SQL queries.
What is affected in CVE-2025-8936?
CVE-2025-8936 affects the unknown functionality of the select2 argument in the Sales Management System.