Code-Projects Simple Stock System是Code-Projects开源的一个简单股票系统。 Code-Projects Simple Stock System 1.0版本存在安全漏洞,该漏洞源于对文件/market/signup.php中参数Username的错误操作,可能导致SQL注入攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| code-projects | Simple Stock System | 1.0 |
cpe:2.3:a:code-projects:simple_stock_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-14968 | 7.3 HIGH | code-projects Simple Stock System update.php sql injection |
| CVE-2025-14961 | 7.3 HIGH | code-projects Simple Blood Donor Management System editedcampaign.php sql injection |
| CVE-2025-14960 | 7.3 HIGH | code-projects Simple Blood Donor Management System editeddonor.php sql injection |
| CVE-2025-14951 | 7.3 HIGH | code-projects Scholars Tracking System home.php sql injection |
| CVE-2025-14950 | 7.3 HIGH | code-projects Scholars Tracking System delete_post.php sql injection |
| CVE-2025-14940 | 7.3 HIGH | code-projects Scholars Tracking System delete_user.php sql injection |
| CVE-2025-14939 | 4.7 MEDIUM | code-projects Online Appointment Booking System deletemanager.php sql injection |
| CVE-2025-14962 | 4.3 MEDIUM | code-projects Simple Stock System chatuser.php cross site scripting |
No comments yet