CVE-2025-15410
HIGHAnisha Online Guitar Store - Injection
Title source: ruleDescription
A vulnerability was identified in code-projects Online Guitar Store 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument L_email leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
References (5)
Scores
CVSS v3
7.3
EPSS
0.0004
EPSS Percentile
10.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-74
CWE-89
Status
published
Affected Products (1)
anisha/online_guitar_store
Timeline
Published
Jan 01, 2026
Tracked Since
Feb 18, 2026