PT-2025-53681 · Itsourcecode · Online Cake Ordering System
Laney
·
Published
2025-12-29
·
Updated
2026-01-02
·
CVE-2025-15166
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
itsourcecode Online Cake Ordering System version 1.0
Description
A SQL injection issue exists in itsourcecode Online Cake Ordering System version 1.0. The issue is located in an unknown function within the
/updatesupplier.php?action=edit file. Manipulation of the ID argument can lead to SQL injection. The attack can be initiated remotely. The exploit for this issue has been publicly released.Recommendations
versions prior to 1.0 should be updated. As a temporary workaround, consider restricting access to the
/updatesupplier.php?action=edit file until a patch is available. Avoid using the ID parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Online Cake Ordering System