PT-2025-41137 · Unknown · Puneethreddyhc Online-Shopping-System-Advanced

Hafizgemilang

·

Published

2025-10-07

·

Updated

2025-10-07

·

CVE-2025-52021

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PuneethReddyHC Online Shopping System Advanced version 1.0
Description A SQL Injection issue exists in the edit product.php file. The product id GET parameter is passed to a SQL query without sufficient validation or parameterization. This could allow for unauthorized access to or modification of data.
Recommendations Apply proper input validation and parameterization techniques to the product id GET parameter in the edit product.php file.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-52021

Affected Products

Puneethreddyhc Online-Shopping-System-Advanced