CVE-2025-0174
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 3, 2025
Updated: Feb 25, 2025
CWE ID 74
CWE ID 89
Summary
CVE-2025-0174 is a critical vulnerability affecting the Point of Sales and Inventory Management System 1.0 by code-projects. The issue lies within the Parameter Handler component of the /user/search_result2.php file. An attacker can exploit this SQL injection weakness by manipulating the search argument, allowing for remote code execution. The exploit has already been made public, increasing the risk for potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Code Projects