CVE-2025-15167: itsourcecode Online Cake Ordering System detailtransac.php sql injection
A vulnerability was determined in itsourcecode Online Cake Ordering System 1.0. This impacts an unknown function of the file /detailtransac.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15167?
CVE-2025-15167 is considered a high severity vulnerability due to the potential for remote SQL injection.
How do I fix CVE-2025-15167?
To fix CVE-2025-15167, sanitize and validate all user inputs to prevent SQL injection in the /detailtransac.php file.
What systems are affected by CVE-2025-15167?
CVE-2025-15167 affects version 1.0 of the itsourcecode Online Cake Ordering System.
Can CVE-2025-15167 be exploited remotely?
Yes, CVE-2025-15167 can be exploited remotely, allowing attackers to execute arbitrary SQL commands.
What is the primary impact of CVE-2025-15167?
The primary impact of CVE-2025-15167 is unauthorized access to sensitive data through SQL injection.