CVE-2025-55444

Published
View on NVD ↗
CVSS v3
9.8
CRITICAL
CVSS v2
N/A
Affected
2
PROJECTS

Description

A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts MCA Project 1.0. A remote attacker can inject arbitrary SQL queries, leading to database enumeration and potential remote code execution.

Online Artwork and Fine Arts is a place where Artwork to display and sell. So for doing this they have to go to the exhibition with his artworks so that anyone can come to the exhibition and buy the desirable art-work.
GitHubGitHub
7