SQL Injection Vulnerability in PuneethReddyHC Online Shopping System
CVE-2025-51972

6.5MEDIUM

Key Information:

Vendor
CVE Published:
28 August 2025

What is CVE-2025-51972?

A SQL Injection vulnerability has been identified in the login.php component of the PuneethReddyHC Online Shopping System Advanced 1.0. This vulnerability arises from the inadequate sanitization of user-supplied input within the keyword POST parameter, allowing malicious actors to inject SQL commands. Exploitation of this flaw could potentially lead to unauthorized access to sensitive data stored in the database or manipulation of the database itself.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.