CVE Details
Basic Information
| Title | code-projects Simple Pizza Ordering System adding-exec.php sql injection |
|---|---|
| Type | cve |
| Published | 2025-06-20T20:00:14.259Z |
| Last Seen |
Product Information
| Vendor | code-projects |
|---|---|
| Product | Simple Pizza Ordering System |
| Version | 1.0 |
CVSS Information
| Base Score | 6.9 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A SQL injection vulnerability in the Simple Pizza Ordering System allows remote attackers to inject malicious SQL code, potentially leading to data theft or system compromise. This issue is critical but may have limited impact due to the niche nature of the product. |
|---|---|
| AI Severity | Medium |
| Vendor | code-projects |
| Product | Simple Pizza Ordering System |
| Affected Version | 1.0 |
Affected Products
- code-projects Simple Pizza Ordering System 1.0
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-89, CWE-74 |
| Bulletin Family |
References
Description
A vulnerability, which was classified as critical, was found in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /adding-exec.php. The manipulation of the argument ingname leads to sql injection. It is possible to launch the attack remotely.