SQL Injection Vulnerability in Code-Projects Point of Sales and Inventory Management System
CVE-2025-0199

6.5MEDIUM

Key Information:

Vendor
CVE Published:
3 January 2025

Summary

A vulnerability has been identified in the Code-Projects Point of Sales and Inventory Management System that enables SQL injection attacks via the /user/minus_cart.php file. The vulnerability arises due to improper handling of user-supplied input, particularly the 'id' parameter. An attacker can exploit this weakness remotely, potentially leading to unauthorized access to sensitive databases and manipulation of critical data. The exploit has been made publicly available, escalating the urgency for users of this software to implement appropriate security measures.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2025-0199 : SQL Injection Vulnerability in Code-Projects Point of Sales and Inventory Management System | SecurityVulnerability.io