CVE-2025-0197
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 3, 2025
Updated: Feb 25, 2025
CWE ID 74
CWE ID 89
Summary
CVE-2025-0197 is a critical vulnerability affecting the code-projects Point of Sales and Inventory Management System 1.0. This issue lies in the unknown code of the file /user/search.php, which can be exploited through manipulation of an argument name. The attack can be launched remotely and has been disclosed to the public, potentially increasing the risk of exploitation. SQL injection is the attack vector used in this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Code Projects