PT-2025-52847 · Unknown · Puneethreddyhc Event Management
Amaan Siddiqui
+1
·
Published
2025-12-23
·
Updated
2026-01-06
·
CVE-2025-65354
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PuneethReddyHC event-management version 1.0
Description
Improper input handling in the
/Grocery/search products itname.php file allows for SQL injection via the sitem name POST parameter. Crafted payloads can alter query logic and disclose database contents, potentially leading to sensitive data disclosure and backend compromise. The sitem name parameter is vulnerable to exploitation.Recommendations
For PuneethReddyHC event-management version 1.0, sanitize or validate the
sitem name POST parameter to prevent SQL injection attacks. As a temporary workaround, restrict access to the /Grocery/search products itname.php file until a proper fix is implemented.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Puneethreddyhc Event Management