CVE-2025-11251
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to manipulate the database of the Dayneks E-Commerce Platform, potentially gaining access to sensitive information or altering data. It can be exploited through specially crafted input on the platform, and it remains a risk until at least February 2026.
Technical Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows SQL Injection.This issue affects E-Commerce Platform: through 27022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Feb 27, 2026
about 1 month ago
Last Modified
Feb 27, 2026
about 1 month ago
Vendor
daynex
Product
woyio