CVE-2025-14251: code-projects Online Ordering System Admin Login admin sql injection
A security vulnerability has been detected in code-projects Online Ordering System 1.0. This affects an unknown function of the file /admin/ of the component Admin Login. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14251?
CVE-2025-14251 is classified as a high severity SQL injection vulnerability.
How do I fix CVE-2025-14251?
To fix CVE-2025-14251, validate and sanitize all user inputs, specifically the Username parameter in the admin login.
What systems are affected by CVE-2025-14251?
CVE-2025-14251 affects the code-projects Online Ordering System version 1.0.
Can CVE-2025-14251 be exploited remotely?
Yes, CVE-2025-14251 can be exploited remotely through the admin login interface.
What type of attacks can CVE-2025-14251 enable?
CVE-2025-14251 allows attackers to execute SQL injection attacks potentially compromising database security.