CVE-2025-14218: code-projects Currency Exchange System editotheraccount.php sql injection
A security flaw has been discovered in code-projects Currency Exchange System 1.0. The affected element is an unknown function of the file /editotheraccount.php. Performing manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14218?
CVE-2025-14218 has been classified as a high severity vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-14218?
To fix CVE-2025-14218, sanitize and validate all user inputs for the ID parameter in the /editotheraccount.php file to prevent SQL injection.
What systems are affected by CVE-2025-14218?
CVE-2025-14218 affects the Currency Exchange System version 1.0 developed by code-projects.
What type of vulnerability is CVE-2025-14218?
CVE-2025-14218 is classified as an SQL Injection vulnerability that can be exploited remotely.
What can attackers do with CVE-2025-14218?
Attackers can exploit CVE-2025-14218 to manipulate database queries, potentially accessing or altering sensitive data.