PT-2025-41137 · Unknown · Puneethreddyhc Online-Shopping-System-Advanced

·

CVE-2025-52021

·

Published

2025-10-07

·

Updated

2025-10-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PuneethReddyHC Online Shopping System Advanced version 1.0
Description A SQL Injection issue exists in the edit product.php file. The product id GET parameter is passed to a SQL query without sufficient validation or parameterization. This could allow for unauthorized access to or modification of data.
Recommendations Apply proper input validation and parameterization techniques to the product id GET parameter in the edit product.php file.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-52021

Affected Products

Puneethreddyhc Online-Shopping-System-Advanced