Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/amaansiddd787/CVE-2025-65354 |
|
Tue, 06 Jan 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:puneethreddyhc:event_management:1.0:*:*:*:*:*:*:* |
Tue, 30 Dec 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 30 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 24 Dec 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Puneethreddyhc
Puneethreddyhc event Management |
|
| Vendors & Products |
Puneethreddyhc
Puneethreddyhc event Management |
Tue, 23 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
ssvc
|
Tue, 23 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injection via the sitem_name POST parameter. Crafted payloads can alter query logic and disclose database contents. Exploitation may result in sensitive data disclosure and backend compromise. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-30T17:37:03.514Z
Reserved: 2025-11-18T00:00:00.000Z
Link: CVE-2025-65354
Updated: 2025-12-23T19:58:15.340Z
Status : Analyzed
Published: 2025-12-23T20:15:46.843
Modified: 2026-01-06T17:17:13.653
Link: CVE-2025-65354
No data.
OpenCVE Enrichment
Updated: 2025-12-24T11:53:23Z