
Technical disclosure and proof-of-concept for SQL injection in PuneethReddyHC event-management v1.0, detailing affected endpoint, payloads, and mitigation.
An SQL Injection vulnerability exists in the PuneethReddyHC event-management application version 1.0 due to improper input handling.
SQL Injection
Endpoint: /Grocery/search_products_itname.php Parameter: sitem_name (POST)
Remote
A remote, unauthenticated attacker can manipulate SQL queries by injecting crafted payloads into the sitem_name POST parameter. Successful exploitation may allow alteration of query logic and disclosure of database contents, potentially leading to sensitive data exposure and backend compromise.
PuneetethReddyHC event-management v1.0
Boolean-based SQL injection payloads were used to demonstrate the issue. Example payloads:
-1' OR 5*5=25 --
-1' OR 5*5=26 --
-1' OR 231=6 AND 000648=000648 --
Use parameterized queries or prepared statements, validate and whitelist user input, enforce strict input length and character restrictions, and run the database with least-privilege permissions.
Discovered by Amaan Siddiqui GitHub: https://github.com/amaansiddd787
CVE-2025-65354