CVE-2025-6668
Last modified
CVE-2025-6668 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. This affects an unknown part of the file /php_action/fetchSelectedBrand.php. The manipulation of the argument brandId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Code-Projects | Inventory Management System | 1.0 |
References
- https://code-projects.org/Product
- https://github.com/lijingze-eng/cve/issues/1Exploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?ctiid.313881Permissions Required, VDB Entry
- https://vuldb.com/?id.313881Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.602340Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-6668?
How severe is CVE-2025-6668?
How do I fix CVE-2025-6668?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-66660Insufficient parameter sanitization in TEE SOC Driver could …1.8
- CVE-2025-66664Insufficient parameter sanitization in AMD Secure Processor …4.6
- CVE-2025-6667A vulnerability was found in code-projects Car Rental System…8.8
- CVE-2025-66675Denial of Service vulnerability in Apache Struts, file leak …8.2
- CVE-2025-66676An issue in IObit Unlocker v1.3.0.11 allows attackers to cau…6.2
- CVE-2025-66678An issue in the HwRwDrv.sys component of Nil Hardware Editor…9.8
- CVE-2025-66680An issue in the WiseDelfile64.sys component of WiseCleaner W…7.1
- CVE-2025-66686A stored Cross-Site Scripting (XSS) vulnerability exists in …6.1
- CVE-2025-66687Doom Launcher 3.8.1.0 is vulnerable to Directory Traversal d…7.5
- CVE-2025-66689A path traversal vulnerability exists in Zen MCP Server befo…6.5
- CVE-2025-6669A vulnerability was found in gooaclok819 sublinkX up to 1.8.…3.7
- CVE-2025-66692A buffer over-read in the PublicKey::verify() method of Bina…7.5
Are you affected by CVE-2025-6668?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
