PT-2025-29351 · Unknown · Modern Bag

·

CVE-2025-7508

·

Published

2025-07-12

·

Updated

2025-07-18

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Modern Bag version 1.0
Description: A critical vulnerability exists due to a SQL injection flaw in the /admin/product-update.php file. The idProduct argument is susceptible to manipulation, potentially allowing for remote attacks. The exploit for this issue has been publicly disclosed.
Recommendations: As a temporary workaround, restrict access to the /admin/product-update.php file. Sanitize the idProduct argument to prevent SQL injection attacks.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-7508

Affected Products

Modern Bag