Threats Tagged 'cve-2025-69564'
View all threats tagged with 'cve-2025-69564'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-69564'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2025-69564 is a critical SQL Injection vulnerability affecting the code-projects Mobile Shop Management System 1.0. The flaw exists in the /ExAddNewUser.php endpoint, where multiple parameters including Name, Address, email, UserName, Password, confirm_password, Role, Branch, and Activate are vulnerable to injection. This vulnerability allows an unauthenticated attacker to execute arbitrary SQL commands remotely without user interaction, potentially leading to full compromise of the backend database. The CVSS score is 9.8, indicating high impact on confidentiality, integrity, and availability. Although no known exploits are currently in the wild, the ease of exploitation and critical impact make this a severe threat. European organizations using this system, especially retail and shop management businesses, face risks of data breaches, data manipulation, and service disruption. Immediate mitigation involves input validation, parameterized queries, and applying patches once available. Join the discussion | CVE Database V5 | 01/27/2026, 00:00:00 UTC Added: 01/27/2026, 16:35:56 UTC |
Showing 1 to 1 of 1 result