VulnerabilityAnalyzed
CVE-2025-14251
A security vulnerability has been detected in code-projects Online Ordering System 1.0.
MEDIUM 5.5EPSS 0.39%
Does this matter?
Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.
Description
A security vulnerability has been detected in code-projects Online Ordering System 1.0. This affects an unknown function of the file /admin/ of the component Admin Login. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
- CVSS 4.0
- 5.5 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.39% probability · 32th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-89
- Affected
- fabian/online ordering system
- Source
- cna@vuldb.com
References
- https://code-projects.org/Product
- https://github.com/zzb1388/cve/issues/95Exploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?ctiid.334761Permissions Required, VDB Entry
- https://vuldb.com/?id.334761Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.702467Third Party Advisory, VDB Entry
- https://github.com/zzb1388/cve/issues/95Exploit, Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.