SQL Injection Vulnerability in Simple E-Commerce Bookstore by SourceCodester
CVE-2025-11476
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 8 October 2025
Badges
What is CVE-2025-11476?
An SQL injection vulnerability has been discovered in the Simple E-Commerce Bookstore software, specifically affecting the /index.php file. This flaw allows attackers to manipulate the login_username argument, potentially enabling remote exploitation. Given that the exploit is available publicly, this poses a significant risk to systems running this application. Organizations using Simple E-Commerce Bookstore 1.0 should take immediate action to patch the vulnerability and secure their applications against potential unauthorized access.
Affected Version(s)
Simple E-Commerce Bookstore 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved