Critical severity9.8NVD Advisory· Published Aug 22, 2025· Updated Jun 17, 2026
CVE-2025-51092
CVE-2025-51092
Description
The LogIn-SignUp project by VishnuSivadasVS is vulnerable to SQL Injection due to unsafe construction of SQL queries in DataBase.php. The functions logIn() and signUp() build queries by directly concatenating user input and unvalidated table names without using prepared statements. While a prepareData() function exists, it is insufficient to prevent SQL injection and does not sanitize the table name.
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)
- cpe:2.3:a:vishnusivadas:login-signup:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- abimelsbk.hashnode.dev/sql-injection-vulnerability-at-login-signup-php-projectnvdThird Party Advisory
News mentions
0No linked articles in our index yet.