SQL Injection Vulnerability in 1000 Projects Bookstore Management System by 1000 Projects
CVE-2025-1173
5.1MEDIUM
Key Information:
- Vendor
- 1000 Projects
- Status
- Bookstore Management System
- Vendor
- CVE Published:
- 11 February 2025
Summary
The 1000 Projects Bookstore Management System version 1.0 has a vulnerability in the file process_users_del.php, where an improper handling of the 'id' parameter allows an attacker to execute SQL injection attacks. This flaw can be exploited remotely, potentially leading to unauthorized access to the database, data manipulation, and exposure of sensitive information. It emphasizes the importance of implementing input validation and secure coding practices to mitigate such risks.
Affected Version(s)
Bookstore Management System 1.0
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Neo-O (VulDB User)