CVE-2025-51970
A SQL Injection vulnerability exists in the action.php endpoint of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter.
- Affected products
- Puneethreddyhc Online-Shopping-System-Advanced
- Puneethreddyhc Online Shopping System Advanced
- = 1.0
- Fix
- Available
- CVSS 3.1
- 7.7 HIGH
- EPSS
- 0.2% (16th percentile)
- Weakness
- CWE-89
- NVD status
- Analyzed
- Published
- 2025-07-29
CVE-2025-51970 at NVD
2 known exploits for CVE-2025-51970
Proof-of-concept code and exploit modules indexed by Sploitus