CVE-2025-4870: itsourcecode Restaurant Management System menu_save.php sql injection
Published May 18, 2025
·Updated
A vulnerability classified as critical was found in itsourcecode Restaurant Management System 1.0. This vulnerability affects unknown code of the file /admin/menusave.php. The manipulation of the argument menu leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
itsourcecode Restaurant Management System
Adonesevangelista Restaurant Management System=1.0
Event History
May 18, 2025
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-4870?
CVE-2025-4870 is classified as a critical vulnerability.
2
How do I fix CVE-2025-4870?
To fix CVE-2025-4870, sanitize and validate user inputs to prevent SQL injection attacks.
3
What software is affected by CVE-2025-4870?
CVE-2025-4870 affects the itsourcecode Restaurant Management System version 1.0.
4
Can CVE-2025-4870 be exploited remotely?
Yes, CVE-2025-4870 can be exploited remotely through a SQL injection vector.
5
Which file is vulnerable in CVE-2025-4870?
The vulnerable file in CVE-2025-4870 is /admin/menu_save.php.