CVE-2025-11594
MEDIUM EPSS 25.6%
Published Oct 11, 20258mo ago · Modified Jun 17, 20261w ago
5.5 CVSS 4.0
Published Oct 11, 2025 8mo ago
Last Modified Jun 17, 2026 1w ago
Description
A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore Website up to 0e0b9f542f7a2d90a8d7f8c83caca69294e234e4. This issue affects some unknown processing of the file /index.php of the component Quantity Handler. Such manipulation leads to improper validation of specified quantity in input. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope X
Threat Intelligence
EPSS Exploit Probability
25.6% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 2
CWE-1284
CWE-703
References 4
- github.com https://github.com/Lianhaorui/Report/blob/main/Payment%20Logic%20Vulnerability.docx
- vuldb.com https://vuldb.com/?ctiid.327915
- vuldb.com https://vuldb.com/?id.327915
- vuldb.com https://vuldb.com/?submit.671737
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.