PT-2025-53710 · Unknown · Refugee Food Management System

Chenxiaodong

·

Published

2025-12-29

·

Updated

2025-12-30

·

CVE-2025-15183

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Refugee Food Management System version 1.0
Description A security issue exists in code-projects Refugee Food Management System 1.0. The manipulation of the tfid argument in the file '/home/viewtakenfd.php' leads to a SQL injection. The attack can be carried out remotely. The exploit has been disclosed publicly. The vulnerability impacts an unknown function within the specified file.
Recommendations Refugee Food Management System version 1.0: Avoid using the tfid parameter in the '/home/viewtakenfd.php' file until the issue is resolved. As a temporary workaround, consider restricting access to the '/home/viewtakenfd.php' file to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-15183

Affected Products

Refugee Food Management System