SQL Injection Vulnerability in PuneethReddyHC Online Shopping System
CVE-2025-51969

6.5MEDIUM

Key Information:

Vendor
CVE Published:
28 August 2025

What is CVE-2025-51969?

A SQL Injection vulnerability has been identified in the product.php page of the PuneethReddyHC Online Shopping System Advanced version 1.0. This vulnerability arises from the improper validation of the product_id parameter in the GET request, allowing an attacker to manipulate SQL queries. Such exploits can lead to unauthorized access to sensitive information or manipulation of the database, posing significant risks to users and organization data integrity.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.