CVE-2025-65354 - Apache event-management SQL Injection

CVE-2025-65354 - Apache event-management SQL Injection

CVE ID : CVE-2025-65354 Published : Dec. 23, 2025, 8:15 p.m. | 32 minutes ago Description : Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injection via the sitem_name POST parameter. Crafted payloads can alter query logic and disclose database contents. Exploitation may result in sensitive data disclosure and backend compromise. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
CRITICAL
Published
Dec. 23, 2025
Affected Product: php
Impact: SQL injection

Source: Telegram CVE Monitor