216.73.217.80

CVE-2025-0207

· Published 04/01/2025 13:15 · Modified 10/01/2025 21:27

Labels: CVE-2025-0207 2025-01-04CVE-2025-0207CWE-74CWE-89[email protected]

Essential information

Published
04/01/2025 13:15
Modified
10/01/2025 21:27
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /function/login.php. The manipulation of the argument password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
code-projects / online shoe store cpe:2.3:a:code-projects:online_shoe_store:1.0:*:*:*:*:*:*:*

References