PT-2025-29466 · Unknown · Simple Php Shopping Cart
Zzb1
·
Published
2025-07-14
·
Updated
2025-07-14
·
CVE-2025-7607
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Simple Shopping Cart version 1.0
Description:
A critical issue exists in the processing of the
/Customers/save order.php file. Manipulation of the order price argument can lead to SQL injection. This issue may be exploited remotely, and details about the exploit have been publicly disclosed.Recommendations:
As a temporary workaround, consider restricting access to the
/Customers/save order.php file until a fix is available.
Avoid using the order price parameter in the affected file until the issue is resolved.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Simple Php Shopping Cart