VulnerabilityAnalyzed
CVE-2025-14229
A security vulnerability has been detected in SourceCodester Inventory Management System 1.0.
LOW 2.0EPSS 0.35%
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
A security vulnerability has been detected in SourceCodester Inventory Management System 1.0. The affected element is an unknown function of the component SVC Report Export. Such manipulation leads to csv injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
- CVSS 4.0
- 2.0 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.35% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-1236
- Affected
- warren-daloyan/inventory management system
- Source
- cna@vuldb.com
References
- https://vuldb.com/?ctiid.334671Permissions Required, VDB Entry
- https://vuldb.com/?id.334671Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.702119Third Party Advisory, VDB Entry
- https://www.notion.so/Spreadsheet-Formula-Injection-Leading-to-Remote-Code-Execution-in-SourceCodester-Inventory-Managemen-2b723917db8c80dfaaabe2b74d6f283d?source=copy_linkExploit, Mitigation, Third Party Advisory
- https://www.sourcecodester.com/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.