SQL Injection Vulnerability in PuneethReddyHC Online Shopping System Advanced
CVE-2025-51968

6.5MEDIUM

Key Information:

Vendor
CVE Published:
28 August 2025

What is CVE-2025-51968?

A SQL Injection vulnerability has been identified in the action.php file of the PuneethReddyHC Online Shopping System Advanced version 1.0. This issue arises due to the application's inability to correctly sanitize the user input provided through the proId POST parameter. As a result, attackers can craft malicious SQL queries that are executed against the database, potentially leading to unauthorized access, data manipulation, or data leakage. It is crucial for users of this application to be aware of the risks associated with this flaw and to apply necessary security measures.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.