CVE-2025-9012: PHPGurukul Online Shopping Portal Project bill-ship-addresses.php sql injection
A vulnerability was identified in PHPGurukul Online Shopping Portal Project 2.0. This affects an unknown part of the file shopping/bill-ship-addresses.php. The manipulation of the argument billingpincode leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9012?
CVE-2025-9012 has been classified as a critical vulnerability due to its potential for remote SQL injection.
How do I fix CVE-2025-9012?
To fix CVE-2025-9012, ensure proper input validation and sanitization of the 'billingpincode' parameter in the shopping/bill-ship-addresses.php file.
Who is affected by CVE-2025-9012?
CVE-2025-9012 affects users of PHPGurukul Online Shopping Portal Project 2.0.
What type of vulnerability is CVE-2025-9012?
CVE-2025-9012 is an SQL injection vulnerability that can be exploited to manipulate database queries.
Can CVE-2025-9012 be exploited remotely?
Yes, CVE-2025-9012 can be exploited remotely, making it a significant security risk.