CNNVD-202507-3477 Information
Jul 28, 2025
cve
CNNVD ID
CNNVD-202507-3477
Related CVE
- CNNVD Published: 2025-07-28
Description (Chinese)
Code-Projects Online Ordering System是Code-Projects开源的一个在线订购系统。 code-projects Online Ordering System 1.0版本存在注入漏洞,该漏洞源于文件/signup.php中参数firstname的错误操作导致SQL注入。
Description (English)
Code-Projects Online Ordering Systems is an online ordering system open to Code-Projects. Code-project Online Ordering System Version 1.0 has an injection loophole, which results from the error of firstname, the parameter in file/signup.php, which caused the SQL injection.
Hazard Level
Medium
Vulnerability Type
注入
Affected Vendor
Code-Projects
Published
2025-07-28
Last Modified
2026-02-24
References
https://github.com/xiajian-qx/cve-xiajian/issues/2 https://code-projects.org/ https://vuldb.com/?id.317836 https://vuldb.com/?submit.622392 https://vuldb.com/?ctiid.317836 https://access.redhat.com/security/cve/cve-2025-8248
Share on: