Vulnerability Description
A vulnerability classified as critical has been found in Fanli2012 native-php-cms 1.0. This affects an unknown part of the file product_list.php. The manipulation of the argument cat leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Native-Php-Cms Project | Native-Php-Cms | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/Fanli2012/native-php-cms/issues/10ExploitIssue TrackingVendor Advisory
- https://github.com/Fanli2012/native-php-cms/issues/10#issue-2769983658ExploitIssue TrackingVendor Advisory
- https://vuldb.com/?ctiid.291933Permissions RequiredVDB Entry
- https://vuldb.com/?id.291933Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.475255Third Party AdvisoryVDB Entry
- https://github.com/Fanli2012/native-php-cms/issues/10ExploitIssue TrackingVendor Advisory
- https://github.com/Fanli2012/native-php-cms/issues/10#issue-2769983658ExploitIssue TrackingVendor Advisory
FAQ
What is CVE-2025-0488?
CVE-2025-0488 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability classified as critical has been found in Fanli2012 native-php-cms 1.0. This affects an unknown part of the file product_list.php. The manipulation of the argument cat leads to sql inje...
How severe is CVE-2025-0488?
CVE-2025-0488 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-0488?
Check the references section above for vendor advisories and patch information. Affected products include: Native-Php-Cms Project Native-Php-Cms.