CVE-2025-12314: code-projects Food Ordering System deleteitem.php sql injection
A vulnerability was found in code-projects Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/deleteitem.php. Performing a manipulation of the argument itemID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12314?
The severity of CVE-2025-12314 is considered high due to the potential for remote SQL injection attacks.
How do I fix CVE-2025-12314?
To fix CVE-2025-12314, sanitize and validate the input for the itemID parameter in the /admin/deleteitem.php file.
What systems are affected by CVE-2025-12314?
CVE-2025-12314 affects version 1.0 of the Code-projects Food Ordering System.
Can CVE-2025-12314 be exploited remotely?
Yes, CVE-2025-12314 can be exploited remotely, allowing attackers to manipulate the itemID for SQL injection.
What impact does CVE-2025-12314 have on data security?
CVE-2025-12314 can lead to unauthorized access to the database, potentially exposing sensitive data.