Code-Projects Simple Stock System是Code-Projects开源的一个简单股票系统。 Code-Projects Simple Stock System 1.0版本存在SQL注入漏洞,该漏洞源于文件/market/update.php中未知功能对参数email处理不当,可能导致SQL注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| code-projects | Simple Stock System | 1.0 |
cpe:2.3:a:code-projects:simple_stock_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-14961 | 7.3 HIGH | code-projects Simple Blood Donor Management System editedcampaign.php sql injection |
| CVE-2025-14960 | 7.3 HIGH | code-projects Simple Blood Donor Management System editeddonor.php sql injection |
| CVE-2025-14959 | 7.3 HIGH | code-projects Simple Stock System signup.php sql injection |
| CVE-2025-14951 | 7.3 HIGH | code-projects Scholars Tracking System home.php sql injection |
| CVE-2025-14950 | 7.3 HIGH | code-projects Scholars Tracking System delete_post.php sql injection |
| CVE-2025-14940 | 7.3 HIGH | code-projects Scholars Tracking System delete_user.php sql injection |
| CVE-2025-14939 | 4.7 MEDIUM | code-projects Online Appointment Booking System deletemanager.php sql injection |
| CVE-2025-14962 | 4.3 MEDIUM | code-projects Simple Stock System chatuser.php cross site scripting |
No comments yet