CVE-2025-15183

A security vulnerability has been detected in code-projects Refugee Food Management System 1.0. This impacts an unknown function of the file /home/viewtakenfd.php. The manipulation of the argument tfid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
References
Link Resource
https://code-projects.org/ Product
https://github.com/ctg503/CVE/issues/3 Permissions Required VDB Entry
https://vuldb.com/?ctiid.338568 Third Party Advisory VDB Entry
https://vuldb.com/?id.338568 Third Party Advisory VDB Entry
https://vuldb.com/?submit.721273 Third Party Advisory VDB Entry
https://vuldb.com/?submit.722808 Third Party Advisory VDB Entry
https://vuldb.com/?submit.722809 Third Party Advisory VDB Entry
https://vuldb.com/?submit.722810 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:fabian:refugee_food_management_system:1.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-29 10:15

Updated : 2025-12-30 21:11


NVD link : CVE-2025-15183

Mitre link : CVE-2025-15183

CVE.ORG link : CVE-2025-15183


JSON object : View

Products Affected

fabian

  • refugee_food_management_system
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')