CVE-2025-6936
Last modified
CVE-2025-6936 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been classified as critical. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file /addpro.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Carmelo | Simple Pizza Ordering System | 1.0 |
References
- https://code-projects.org/Product
- https://github.com/Catcheryp/CVE/issues/2Exploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?ctiid.314457Permissions Required
- https://vuldb.com/?id.314457Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.605728Third Party Advisory, VDB Entry
- https://github.com/Catcheryp/CVE/issues/2Exploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-6936?
How severe is CVE-2025-6936?
How do I fix CVE-2025-6936?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-69354Missing Authorization vulnerability in BBR Plugins Better Bu…4.3
- CVE-2025-69355Missing Authorization vulnerability in Tickera Tickera ticke…4.3
- CVE-2025-69356Improper Control of Filename for Include/Require Statement i…7.5
- CVE-2025-69357Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-69358Missing Authorization vulnerability in Metagauss EventPrime …7.5
- CVE-2025-69359Missing Authorization vulnerability in WPFunnels Creator LMS…5.3
- CVE-2025-69360Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-69361Missing Authorization vulnerability in PublishPress Post Exp…4.3
- CVE-2025-69362Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2025-69363Missing Authorization vulnerability in CyberChimps Responsiv…6.5
- CVE-2025-69364Missing Authorization vulnerability in Cloudways Breeze bree…5.3
- CVE-2025-69365Improper Neutralization of Special Elements used in an SQL C…9.3
Are you affected by CVE-2025-6936?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
