Vulnerability Description
Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injection via the sitem_name POST parameter. Crafted payloads can alter query logic and disclose database contents. Exploitation may result in sensitive data disclosure and backend compromise.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Puneethreddyhc | Event Management | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/amaansiddd787/CVE-2025-65354ExploitThird Party Advisory
FAQ
What is CVE-2025-65354?
CVE-2025-65354 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injection via the sitem_name POST parameter. Crafted payloads can alter query logic and...
How severe is CVE-2025-65354?
CVE-2025-65354 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-65354?
Check the references section above for vendor advisories and patch information. Affected products include: Puneethreddyhc Event Management.