SQL Injection Vulnerability in code-projects Online Shoe Store 1.0
CVE-2025-0204
Key Information:
- Vendor
- Code-projects
- Status
- Vendor
- CVE Published:
- 4 January 2025
Badges
Summary
A vulnerability exists within code-projects’ Online Shoe Store version 1.0, specifically in the handling of the 'id' parameter in the /details.php file. This flaw allows an attacker to perform SQL injection, potentially compromising the integrity of the application's database. The issue can be exploited remotely, putting user data and application functionality at risk. Public disclosure of this vulnerability raises critical awareness for developers and system administrators to take immediate action to protect against unauthorized database access. It is essential for users of the affected version to apply appropriate security patches or implement mitigations to safeguard their systems.
Affected Version(s)
Online Shoe Store 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved