PT-2025-52847 · Unknown · Puneethreddyhc Event Management

Amaan Siddiqui

+1

·

Published

2025-12-23

·

Updated

2026-01-06

·

CVE-2025-65354

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PuneethReddyHC event-management version 1.0
Description Improper input handling in the /Grocery/search products itname.php file allows for SQL injection via the sitem name POST parameter. Crafted payloads can alter query logic and disclose database contents, potentially leading to sensitive data disclosure and backend compromise. The sitem name parameter is vulnerable to exploitation.
Recommendations For PuneethReddyHC event-management version 1.0, sanitize or validate the sitem name POST parameter to prevent SQL injection attacks. As a temporary workaround, restrict access to the /Grocery/search products itname.php file until a proper fix is implemented.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-65354

Affected Products

Puneethreddyhc Event Management