SQL Injection Vulnerability in Nero Social Networking Site by Code Projects
CVE-2025-13279
5.3MEDIUM
Key Information:
- Vendor
Code-projects
- Vendor
- CVE Published:
- 17 November 2025
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2025-13279?
A SQL injection vulnerability has been identified in the Nero Social Networking Site version 1.0. It affects an unspecified function in the file /profilefriends.php. This vulnerability arises from improper handling of the argument ID, which allows for manipulation that leads to unauthorized SQL queries. The potential for remote exploitation makes this issue particularly concerning, as it could allow attackers to compromise database integrity and extract sensitive information.
Affected Version(s)
Nero Social Networking Site 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
