Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-65354 — Technical disclosure and proof-of-concept for SQL injection in PuneethReddyHC event-management v1.0, detailing affected endpoint, payloads, and mitigation. | Kitploit
Tools/GitHubGitHub/amaansiddd787/cve-2025-65354
Vulnerability AnalysisWeb Application ExploitationInformation GatheringPenetration TestingLearning & EducationDatabase Security
GitHubamaansiddd787/cve-2025-65354

CVE-2025-65354

Technical disclosure and proof-of-concept for SQL injection in PuneethReddyHC event-management v1.0, detailing affected endpoint, payloads, and mitigation.

View Repository
1189 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-65354 — SQL Injection Vulnerability

Summary

An SQL Injection vulnerability exists in the PuneethReddyHC event-management application version 1.0 due to improper input handling.

Vulnerability Type

SQL Injection

Affected Component

Endpoint: /Grocery/search_products_itname.php Parameter: sitem_name (POST)

Attack Type

Remote

Impact

A remote, unauthenticated attacker can manipulate SQL queries by injecting crafted payloads into the sitem_name POST parameter. Successful exploitation may allow alteration of query logic and disclosure of database contents, potentially leading to sensitive data exposure and backend compromise.

Affected Versions

PuneetethReddyHC event-management v1.0

Proof of Concept

Boolean-based SQL injection payloads were used to demonstrate the issue. Example payloads:

-1' OR 5*5=25 --

-1' OR 5*5=26 --

-1' OR 231=6 AND 000648=000648 --

Mitigation

Use parameterized queries or prepared statements, validate and whitelist user input, enforce strict input length and character restrictions, and run the database with least-privilege permissions.

Credits

Discovered by Amaan Siddiqui GitHub: https://github.com/amaansiddd787

CVE

CVE-2025-65354

Download Tool