CVE-2025-14959: code-projects Simple Stock System signup.php sql injection
A weakness has been identified in code-projects Simple Stock System 1.0. This issue affects some unknown processing of the file /market/signup.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14959?
CVE-2025-14959 is classified as a medium severity vulnerability due to its potential for SQL injection exploitation.
How do I fix CVE-2025-14959?
To fix CVE-2025-14959, sanitize and validate the input in the Username argument to prevent SQL injection.
What impacts does CVE-2025-14959 have on my system?
CVE-2025-14959 can allow attackers to manipulate database queries, potentially leading to unauthorized data access and data breaches.
Can CVE-2025-14959 be exploited remotely?
Yes, CVE-2025-14959 can be exploited remotely due to the nature of the vulnerability in the signup.php file.
Which software is affected by CVE-2025-14959?
CVE-2025-14959 affects the Simple Stock System version 1.0 developed by code-projects.