CVE-2025-14968: code-projects Simple Stock System update.php sql injection
A security flaw has been discovered in code-projects Simple Stock System 1.0. Affected by this issue is some unknown functionality of the file /market/update.php. The manipulation of the argument email results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14968?
CVE-2025-14968 is classified as a high-severity vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-14968?
To fix CVE-2025-14968, sanitize and validate all user inputs, particularly the 'email' parameter in the /market/update.php file.
What systems are affected by CVE-2025-14968?
CVE-2025-14968 affects Code-projects Simple Stock System version 1.0, specifically through the /market/update.php file.
Can CVE-2025-14968 be exploited remotely?
Yes, CVE-2025-14968 can be exploited remotely, allowing attackers to execute SQL injection attacks from anywhere.
What are the potential consequences of exploiting CVE-2025-14968?
Exploiting CVE-2025-14968 could lead to unauthorized access to the database, data manipulation, and potential data breaches.