SQL Injection Vulnerability in Campcodes Complete Online Beauty Parlor Management System
CVE-2025-14990
Key Information:
- Vendor
Campcodes
- Vendor
- CVE Published:
- 21 December 2025
Badges
What is CVE-2025-14990?
A security flaw has been identified in the Campcodes Complete Online Beauty Parlor Management System version 1.0, specifically affecting a function within the file /admin/view-appointment.php. This vulnerability arises from improper handling of the 'viewid' parameter, allowing for SQL injection attacks. Malicious actors can exploit this weakness remotely, potentially leading to unauthorized access to sensitive data. This issue has been publicly disclosed, raising concerns about its exploitation in the wild.
Affected Version(s)
Complete Online Beauty Parlor Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
