PT-2025-16206 · Phpshe · Phpshe

·

CVE-2025-3553

·

Published

2025-04-14

·

Updated

2025-10-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: phpshe version 1.8
Description: A critical issue has been identified, affecting the pe delete function in the /admin.php?mod=brand&act=del endpoint. The manipulation of the brand id[] argument leads to SQL injection. This issue can be exploited remotely.
Recommendations: For phpshe version 1.8, consider disabling the pe delete function in the /admin.php?mod=brand&act=del endpoint until a patch is available. Restrict access to the brand id[] argument to minimize the risk of SQL injection exploitation.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-3553

Affected Products

Phpshe