SQL Injection Vulnerability in 1000 Projects Bookstore Management System by 1000 Projects
CVE-2025-1173

5.1MEDIUM

Key Information:

Vendor
1000 Projects
Status
Bookstore Management System
Vendor
CVE Published:
11 February 2025

Summary

The 1000 Projects Bookstore Management System version 1.0 has a vulnerability in the file process_users_del.php, where an improper handling of the 'id' parameter allows an attacker to execute SQL injection attacks. This flaw can be exploited remotely, potentially leading to unauthorized access to the database, data manipulation, and exposure of sensitive information. It emphasizes the importance of implementing input validation and secure coding practices to mitigate such risks.

Affected Version(s)

Bookstore Management System 1.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Neo-O (VulDB User)
.