PT-2025-51031 · Itsourcecode · Covid Tracking System

·

CVE-2025-14584

·

Published

2025-12-12

·

Updated

2025-12-18

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions itsourcecode COVID Tracking System version 1.0
Description A SQL injection issue exists in the Admin Login component of the software. The issue is located in the /admin/login.php file, specifically within an unknown function. Exploitation occurs through manipulation of the Username parameter, allowing for remote attacks. The exploit details have been publicly disclosed.
Recommendations Apply a fix to the vulnerable function in the /admin/login.php file to prevent SQL injection attacks targeting the Username parameter.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-14584

Affected Products

Covid Tracking System