PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-65336 Fruits-Bazar CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T21:16:50.690Z and has not been modified since then. CVE-2025-65336 is a SQL Injection vulnerability in the /show_price_by_pdtId.php file of Fruits-Bazar 1.0. The vulnerability has a CVSS score of 9.8 and a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. This suggests that the vulnerability can be exploited remotely without authentication, potentially leading to high impact on confidentiality, integrity, and availability. Security teams responsible for ecommerce platforms, particularly those using Fruits-Bazar 1.0, should prioritize this vulnerability. The high CVSS score indicates a critical risk that requires immediate attention to prevent potential SQL Injection attacks. It is essential to verify the inventory of Fruits-Bazar 1.0 installations, implement compensating controls to detect and prevent SQL Injection attacks, monitor for suspicious activity on /show_price_by_pdtId.php, and apply patches or updates if available from the vendor.

Vendor
Fruits-Bazar
Product
Fruits-Bazar 1.0
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-30
Original CVE updated
2026-07-31
Advisory published
2026-07-30
Advisory updated
2026-07-31

Who should care

Security teams responsible for ecommerce platforms, particularly those using Fruits-Bazar 1.0, should prioritize this vulnerability. The high CVSS score indicates a critical risk that requires immediate attention to prevent potential SQL Injection attacks.

Technical summary

CVE-2025-65336 is a SQL Injection vulnerability in the /show_price_by_pdtId.php file of Fruits-Bazar 1.0. The vulnerability has a CVSS score of 9.8 and a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. This suggests that the vulnerability can be exploited remotely without authentication, potentially leading to high impact on confidentiality, integrity, and availability.

Defensive priority

This SQL Injection vulnerability in Fruits-Bazar 1.0 has a critical CVSS score of 9.8. Immediate defensive actions are required to mitigate potential attacks.

Recommended defensive actions

  • Verify the inventory of Fruits-Bazar 1.0 installations
  • Implement compensating controls to detect and prevent SQL Injection attacks
  • Monitor for suspicious activity on /show_price_by_pdtId.php
  • Apply patches or updates if available from the vendor
  • Restrict access to the affected endpoint

Evidence notes

The CVE-2025-65336 record indicates a SQL Injection vulnerability in /show_price_by_pdtId.php of Fruits-Bazar 1.0. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, suggesting a high impact. However, detailed information about the affected product and vendor is limited.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T21:16:50.690Z and has not been modified since then.