SQL Injection Vulnerability in Nero Social Networking Site by Code-Projects
CVE-2025-13277
Key Information:
- Vendor
Code-projects
- Vendor
- CVE Published:
- 17 November 2025
Badges
What is CVE-2025-13277?
A security flaw has been identified in Code-Projects' Nero Social Networking Site version 1.0, specifically within the handling of the /friendsphoto.php file. This vulnerability arises from improper processing of the ID argument, potentially allowing attackers to conduct SQL injection attacks. Exploitation of this issue can occur remotely, posing a significant risk to the integrity of the database and the overall security of the web application. Detailed exploit information is available, making it essential for users to take immediate action to mitigate risks.
Affected Version(s)
Nero Social Networking Site 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
