CVE-2025-6612
Last modified
CVE-2025-6612 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability was found in code-projects Inventory Management System 1.0. It has been rated as critical. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
A vulnerability was found in code-projects Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /php_action/removeCategories.php. The manipulation of the argument categoriesId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Code-Projects | Inventory Management System | 1.0 |
References
- https://code-projects.org/Product
- https://github.com/Lwlej/cve/issues/1Exploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?ctiid.313829Permissions Required, VDB Entry
- https://vuldb.com/?id.313829Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.601977Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-6612?
How severe is CVE-2025-6612?
How do I fix CVE-2025-6612?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-66114Missing Authorization vulnerability in theme funda Show Vari…5.3
- CVE-2025-66115Improper Control of Filename for Include/Require Statement i…6.6
- CVE-2025-66116Insertion of Sensitive Information Into Sent Data vulnerabil…7.5
- CVE-2025-66117Missing Authorization vulnerability in Ays Pro Easy Form eas…7.5
- CVE-2025-66118Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-66119Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-66120Missing Authorization vulnerability in CatFolders CatFolders…5.3
- CVE-2025-66121Missing Authorization vulnerability in SiteGround SiteGround…5.3
- CVE-2025-66122Missing Authorization vulnerability in Design Stylish Price …5.3
- CVE-2025-66123Unauthenticated Insecure Direct Object References (IDOR) in …5.3
- CVE-2025-66124Missing Authorization vulnerability in ZEEN101 Leaky Paywall…5.3
- CVE-2025-66125Insertion of Sensitive Information Into Sent Data vulnerabil…5.3
Are you affected by CVE-2025-6612?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
