SQL Injection Vulnerability in Code-Projects Point of Sales and Inventory Management System
CVE-2025-0199
6.5MEDIUM
What is CVE-2025-0199?
A vulnerability has been identified in the Code-Projects Point of Sales and Inventory Management System that enables SQL injection attacks via the /user/minus_cart.php file. The vulnerability arises due to improper handling of user-supplied input, particularly the 'id' parameter. An attacker can exploit this weakness remotely, potentially leading to unauthorized access to sensitive databases and manipulation of critical data. The exploit has been made publicly available, escalating the urgency for users of this software to implement appropriate security measures.