CVE-2025-14990: Campcodes Complete Online Beauty Parlor Management System view-appointment.php sql injection
A security flaw has been discovered in Campcodes Complete Online Beauty Parlor Management System 1.0. Impacted is an unknown function of the file /admin/view-appointment.php. Performing a manipulation of the argument viewid results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14990?
CVE-2025-14990 is rated as a high severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2025-14990?
To fix CVE-2025-14990, Sanitize and validate all user inputs in the /admin/view-appointment.php file to prevent SQL injection.
What are the potential impacts of CVE-2025-14990?
Exploitation of CVE-2025-14990 could allow an attacker to manipulate database queries, compromising database integrity and obtaining sensitive information.
Can CVE-2025-14990 be exploited remotely?
Yes, CVE-2025-14990 can be exploited remotely, making it critical for administrators to address this vulnerability promptly.
Which software is affected by CVE-2025-14990?
CVE-2025-14990 affects the Campcodes Complete Online Beauty Parlor Management System version 1.0.