CVE-2025-14832: itsourcecode Online Cake Ordering System updateproduct.php sql injection
A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown function of the file /updateproduct.php?action=edit. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14832?
CVE-2025-14832 is considered a high severity vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-14832?
To fix CVE-2025-14832, it is essential to sanitize and validate user inputs on the /updateproduct.php?action=edit endpoint.
What systems are affected by CVE-2025-14832?
The CVE-2025-14832 vulnerability affects the itsourcecode Online Cake Ordering System version 1.0.
Can CVE-2025-14832 be exploited remotely?
Yes, CVE-2025-14832 can be exploited remotely, allowing attackers to execute SQL injection attacks from outside the system.
What kind of attacks can CVE-2025-14832 facilitate?
CVE-2025-14832 can facilitate SQL injection attacks, which may lead to unauthorized access or data manipulation in the database.