SQL Injection Vulnerability in code-projects E-Commerce Website 1.0
CVE-2025-11509
Key Information:
- Vendor
Code-projects
- Status
- Vendor
- CVE Published:
- 8 October 2025
Badges
What is CVE-2025-11509?
A vulnerability was identified in the code-projects E-Commerce Website version 1.0 affecting the /pages/product_add.php file. This vulnerability arises from improper handling of the prod_name
argument, allowing attackers to execute SQL injection attacks remotely. The exploit has been made public, posing a serious threat to systems using this application. It is crucial for users of this software to understand the potential risks and take immediate action to mitigate them.
Affected Version(s)
E-Commerce Website 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved