CVE-2025-13449

Source
https://cve.org/CVERecord?id=CVE-2025-13449
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-13449.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-13449
Published
2025-11-20T15:17:25.953Z
Modified
2026-03-15T22:50:16.202280Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability was found in code-projects Online Shop Project 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument Password results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-13449.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.0"
            }
        ]
    }
]