SQL Injection Vulnerability in SourceCodester Eyewear Shop
CVE-2025-4173
Key Information:
- Vendor
- Sourcecodester
- Status
- Vendor
- CVE Published:
- 1 May 2025
Badges
Summary
A vulnerability exists in the SourceCodester Online Eyewear Shop version 1.0, specifically within the 'delete_cart' function located in /oews/classes/Master.php?f=delete_cart. This issue arises from improper handling of the 'ID' argument, leading to SQL injection possibilities. Attackers can exploit this vulnerability remotely, enabling them to manipulate database queries, potentially compromising sensitive data and application integrity. Given its public disclosure, immediate action is necessary to mitigate risks.
Affected Version(s)
Online Eyewear Shop 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved