CVE-2025-14989: Campcodes Complete Online Beauty Parlor Management System search-invoices.php sql injection
A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This issue affects some unknown processing of the file /admin/search-invoices.php. Such manipulation leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14989?
CVE-2025-14989 is classified as a critical vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-14989?
To fix CVE-2025-14989, ensure that proper input validation and prepared statements are implemented in the /admin/search-invoices.php file.
What software is affected by CVE-2025-14989?
CVE-2025-14989 affects Campcodes Complete Online Beauty Parlor Management System version 1.0.
Can CVE-2025-14989 be exploited remotely?
Yes, CVE-2025-14989 can be exploited remotely, allowing attackers to perform SQL injection from a distance.
What kind of attacks can be performed due to CVE-2025-14989?
CVE-2025-14989 allows attackers to manipulate SQL queries, potentially leading to data leakage or unauthorized access.