CVE-2025-14649: itsourcecode Online Cake Ordering System supplier.php sql injection
A vulnerability was detected in itsourcecode Online Cake Ordering System 1.0. Affected by this issue is some unknown functionality of the file /cakeshop/supplier.php. Performing manipulation of the argument supplier results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14649?
CVE-2025-14649 is classified as a critical vulnerability due to the potential for remote SQL injection leading to data breaches.
How do I fix CVE-2025-14649?
To fix CVE-2025-14649, ensure that user inputs are properly validated and sanitized in the supplier.php file.
What are the potential impacts of exploitation of CVE-2025-14649?
Exploitation of CVE-2025-14649 can allow attackers to execute arbitrary SQL commands, potentially leading to data loss or compromise.
Which systems are affected by CVE-2025-14649?
CVE-2025-14649 affects the itsourcecode Online Cake Ordering System version 1.0.
Is remote exploitation possible for CVE-2025-14649?
Yes, remote exploitation of CVE-2025-14649 is possible, making it critical for organizations to address it promptly.