CVE-2025-15166: itsourcecode Online Cake Ordering System updatesupplier.php sql injection
A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown function of the file /updatesupplier.php?action=edit. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15166?
CVE-2025-15166 has a high severity rating due to its potential for remote SQL injection vulnerabilities.
How do I fix CVE-2025-15166?
To fix CVE-2025-15166, sanitize and validate all inputs in the /updatesupplier.php file to prevent SQL injection.
Who is affected by CVE-2025-15166?
CVE-2025-15166 affects users of the itsourcecode Online Cake Ordering System version 1.0.
Is CVE-2025-15166 exploitable remotely?
Yes, CVE-2025-15166 can be exploited remotely, allowing attackers to manipulate database queries.
What type of vulnerability is CVE-2025-15166?
CVE-2025-15166 is classified as a SQL injection vulnerability, specifically impacting an unknown function in the application.