CVE-2020-25905: Mobile Shop System Project Mobile Shop System

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

An SQL Injection vulnerabilty exists in Sourcecodester Mobile Shop System in PHP MySQL 1.0 via the email parameter in (1) login.php or (2) LoginAsAdmin.php.

Affected products

Published 2022-01-28. Last modified 2026-06-17.