CVE-2025-14638: itsourcecode Online Pet Shop Management System update_cnp.php sql injection
A security vulnerability has been detected in itsourcecode Online Pet Shop Management System 1.0. This issue affects some unknown processing of the file /pet1/updatecnp.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14638?
CVE-2025-14638 is considered a high severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2025-14638?
To fix CVE-2025-14638, sanitize and validate all user inputs, especially the 'ID' parameter in the /pet1/update_cnp.php file.
What systems are affected by CVE-2025-14638?
CVE-2025-14638 affects the itsourcecode Online Pet Shop Management System version 1.0.
Can CVE-2025-14638 be exploited remotely?
Yes, CVE-2025-14638 can be exploited remotely, allowing attackers to perform SQL injection attacks.
What is the attack vector for CVE-2025-14638?
The attack vector for CVE-2025-14638 involves manipulating the 'ID' argument in the /pet1/update_cnp.php file.