CVE-2025-7461

HIGH

code-projects Modern Bag 1.0 - SQL Injection via proId Parameter in /action.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-7461. PoCs published by bx33661.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2025-7461, a SQL injection vulnerability in the Modern Bag E-commerce System (v1.0). It includes root cause analysis, vulnerable code snippets, and attack examples for Boolean-based, Error-based, and Time-based blind SQL injection.

Description

A vulnerability was found in code-projects Modern Bag 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /action.php. The manipulation of the argument proId leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Exploits (1)

nomisec WRITEUP 3 stars
by bx33661 · poc
https://github.com/bx33661/CVE-2025-7461

This repository provides a detailed technical analysis of CVE-2025-7461, a SQL injection vulnerability in the Modern Bag E-commerce System (v1.0). It includes root cause analysis, vulnerable code snippets, and attack examples for Boolean-based, Error-based, and Time-based blind SQL injection.

Classification
Writeup 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Modern Bag E-commerce System v1.0
Auth required
Prerequisites: Access to the vulnerable endpoint /action.php · Valid session (uid)
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.316112
Permissions Required signature permissions-required
https://vuldb.com/?ctiid.316112
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.610055
Exploit, Issue Tracking, Third Party Advisory exploit issue-tracking
https://github.com/bx33661/newvul/issues/1
Product product
https://code-projects.org/

Scores

CVSS v3 7.3
EPSS 0.0040
EPSS Percentile 31.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
code-projects/modern_bag 1.0
Published Jul 12, 2025
Tracked Since Feb 18, 2026