SQL Injection Vulnerability in Code-Projects Point of Sales and Inventory Management System
CVE-2025-0199
6.5MEDIUM
Summary
A vulnerability has been identified in the Code-Projects Point of Sales and Inventory Management System that enables SQL injection attacks via the /user/minus_cart.php file. The vulnerability arises due to improper handling of user-supplied input, particularly the 'id' parameter. An attacker can exploit this weakness remotely, potentially leading to unauthorized access to sensitive databases and manipulation of critical data. The exploit has been made publicly available, escalating the urgency for users of this software to implement appropriate security measures.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published