CVE-2025-14590: code-projects Prison Management System search1.php sql injection
A security vulnerability has been detected in code-projects Prison Management System 2.0. Impacted is an unknown function of the file /admin/search1.php. The manipulation of the argument keyname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14590?
CVE-2025-14590 has been categorized with a critical severity due to its potential for SQL injection attacks.
How do I fix CVE-2025-14590?
To fix CVE-2025-14590, validate and sanitize all user inputs to prevent SQL injection vulnerabilities.
What systems are affected by CVE-2025-14590?
CVE-2025-14590 affects version 2.0 of the Code-projects Prison Management System.
Can CVE-2025-14590 be exploited remotely?
Yes, CVE-2025-14590 can be exploited remotely due to its nature as a SQL injection vulnerability.
What is the nature of the vulnerability in CVE-2025-14590?
CVE-2025-14590 is an SQL injection vulnerability caused by the manipulation of the 'keyname' argument in the /admin/search1.php file.