CVE-2025-14637: itsourcecode Online Pet Shop Management System addcnp.php sql injection
A weakness has been identified in itsourcecode Online Pet Shop Management System 1.0. This vulnerability affects unknown code of the file /pet1/addcnp.php. This manipulation of the argument cnpname causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14637?
CVE-2025-14637 has a high severity due to its potential for SQL injection vulnerabilities that can be exploited remotely.
How do I fix CVE-2025-14637?
To fix CVE-2025-14637, sanitize and validate all user inputs, particularly the 'cnpname' parameter in the /pet1/addcnp.php file.
Which software is affected by CVE-2025-14637?
CVE-2025-14637 affects the itsourcecode Online Pet Shop Management System version 1.0.
Can CVE-2025-14637 be exploited remotely?
Yes, CVE-2025-14637 can be exploited remotely, allowing attackers to manipulate SQL queries.
What specific file is implicated in CVE-2025-14637?
The specific file implicated in CVE-2025-14637 is /pet1/addcnp.php.