SQL Injection Vulnerability in Simple Pizza Ordering System by Code-Projects
CVE-2025-6482
Key Information:
- Vendor
Code-projects
- Vendor
- CVE Published:
- 22 June 2025
Badges
What is CVE-2025-6482?
A vulnerability exists in the Simple Pizza Ordering System 1.0, specifically in the edituser-exec.php file, where an attacker can manipulate the 'userid' argument to execute SQL injection attacks. This allows unauthorized access to the database, potentially exposing sensitive user information. The exploit can be executed remotely, posing a serious threat to the integrity and confidentiality of the application's data. Users of the affected version should take immediate action to secure their systems and prevent exploitation.
Affected Version(s)
Simple Pizza Ordering System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved