CNNVD-202512-606 Information

CNNVD ID

CNNVD-202512-606

CVE-2025-14091

  • CNNVD Published: 2025-12-05

Description (Chinese)

PHP-Guitar-Shop是Konrad个人开发者的一个吉他店网站。 PHP-Guitar-Shop存在SQL注入漏洞,该漏洞源于对文件/product.php中参数ID的错误操作,可能导致SQL注入攻击。

Description (English)

PHP-Guitar-Shop is a guitar shop site for Konrad personal developers. PHP-Guitar-Shop has an injection loophole in SQL, which stems from the wrong operation of parameter ID in document/product.php, which could lead to an attack on SQL.

Hazard Level

Medium

Vulnerability Type

SQL注入

Affected Vendor

个人开发者

Published

2025-12-05

Last Modified

2026-02-24

References

https://github.com/appaxv/report/blob/main/guitarshopsql.docx https://vuldb.com/?ctiid.334481 https://vuldb.com/?id.334481 https://vuldb.com/?submit.696514 https://access.redhat.com/security/cve/cve-2025-14091

Share on: