CVE-2025-4864: itsourcecode Restaurant Management System finished.php sql injection
Published May 18, 2025
·Updated
A vulnerability has been found in itsourcecode Restaurant Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/finished.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
itsourcecode Restaurant Management System
Adonesevangelista Restaurant Management System=1.0
Event History
May 18, 2025
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-4864?
CVE-2025-4864 is classified as a critical vulnerability.
2
How do I fix CVE-2025-4864?
To fix CVE-2025-4864, sanitize and validate user inputs to prevent SQL injection vulnerabilities.
3
What type of attack does CVE-2025-4864 allow?
CVE-2025-4864 allows for remote SQL injection attacks due to improper handling of the ID argument.
4
Which software is affected by CVE-2025-4864?
CVE-2025-4864 affects the itsourcecode Restaurant Management System 1.0.
5
Where does the vulnerability CVE-2025-4864 manifest in the software?
The vulnerability CVE-2025-4864 is found in the file /admin/finished.php.