PT-2025-49506 · Unknown · Currency Exchange System

Yudeshui

·

Published

2025-12-08

·

Updated

2026-01-03

·

CVE-2025-14216

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Currency Exchange System version 1.0
Description A flaw exists in code-projects Currency Exchange System 1.0 where manipulation of the ID argument in the /viewserial.php file can lead to SQL injection. This issue is remotely exploitable and an exploit has been publicly disclosed. The vulnerability involves unknown processing of the file.
Recommendations Versions prior to 1.0 should be updated. As a temporary workaround, restrict access to the /viewserial.php file to minimize the risk of exploitation. Avoid using the ID parameter in the /viewserial.php API endpoint until the issue is resolved.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-14216

Affected Products

Currency Exchange System