SQL Injection Vulnerability in Online Complaint Site by Code-Projects
CVE-2025-63622
9.8CRITICAL
What is CVE-2025-63622?
A security flaw has been identified in Code-Projects' Online Complaint Site version 1.0, specifically related to improper handling of inputs in the /cms/admin/subcategory.php file. This vulnerability permits attackers to manipulate the 'category' parameter, leading to potential SQL injection. Exploiting this vulnerability could allow unauthorized access to the database, manipulation of data, or the retrieval of sensitive information.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
