CVE-2025-14250: code-projects Online Ordering System user_contact.php sql injection
A weakness has been identified in code-projects Online Ordering System 1.0. The impacted element is an unknown function of the file /usercontact.php. This manipulation of the argument Name causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14250?
CVE-2025-14250 is considered a high severity vulnerability due to its ability to facilitate SQL injection attacks.
How do I fix CVE-2025-14250?
To fix CVE-2025-14250, sanitize and validate user input in the /user_contact.php file to prevent SQL injection.
What is affected by CVE-2025-14250?
CVE-2025-14250 affects the Code-projects Online Ordering System version 1.0.
Can CVE-2025-14250 be exploited remotely?
Yes, CVE-2025-14250 can be exploited remotely, allowing attackers to manipulate SQL queries.
What type of vulnerability is CVE-2025-14250?
CVE-2025-14250 is classified as an SQL injection vulnerability.