CVE-2025-14285: code-projects Employee Profile Management System edit_personnel.php sql injection
Published Dec 9, 2025
·Updated
A vulnerability was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file editpersonnel.php. The manipulation of the argument perid results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
Affected Software
2 affected components
Code-projects Employee Profile Management System=1.0
Code-projects Employee Profile Management System=1.0
Event History
Dec 9, 2025
CVE Published
via MITRE·01:02 AM
Data Sourced
via MITRE·01:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-14285?
CVE-2025-14285 is classified as a critical vulnerability due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2025-14285?
To fix CVE-2025-14285, sanitize and validate all user inputs, especially for the per_id parameter in edit_personnel.php.
3
What type of attack does CVE-2025-14285 enable?
CVE-2025-14285 enables SQL injection attacks that can be exploited remotely.
4
Which version of Employee Profile Management System is affected by CVE-2025-14285?
CVE-2025-14285 affects version 1.0 of the Employee Profile Management System.
5
What file is associated with CVE-2025-14285?
CVE-2025-14285 is associated with the file edit_personnel.php.