CVE-2025-10802 | code-projects Online Bidding System 1.0 remove.php ID sql injection
A vulnerability identified as critical has been detected in code-projects Online Bidding System 1.0. Affected is an unknown function of the file /administrator/remove.php. This manipulation of the argument ID causes sql injection.
The identification of this vulnerability is CVE-2025-10802. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.