Unknown · Code-Projects Online Shopping Store · CVE-2025-6484
Name of the Vulnerable Software and Affected Versions:
code-projects Online Shopping Store version 1.0
Description:
A critical issue affects an unknown functionality of the file /action.php. The manipulation of the arguments `cat id`, `brand id`, `keyword`, `proId`, `pid` leads to SQL injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Recommendations:
As a temporary workaround, consider restricting access to the /action.php file until a patch is available.
Avoid using the parameters `cat id`, `brand id`, `keyword`, `proId`, `pid` in the affected functionality until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.