SQL Injection Vulnerability in Code-Projects Vehicle Management by Code-Projects
CVE-2025-8375
Key Information:
- Vendor
Code-projects
- Status
- Vendor
- CVE Published:
- 31 July 2025
Badges
What is CVE-2025-8375?
A vulnerability has been identified in Code-Projects Vehicle Management 1.0, specifically in the /addvehicle.php file, where improper input handling allows for SQL injection attacks. This flaw enables attackers to manipulate the 'vehicle' argument, potentially allowing them to execute unauthorized SQL commands on the database. The exploit is accessible remotely, posing significant risks to data integrity and confidentiality. Mitigation measures are recommended to safeguard against potential exploitation.
Affected Version(s)
Vehicle Management 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved