SQL Injection Vulnerability in itsourcecode Online Frozen Foods Ordering System
CVE-2025-15073
Key Information:
- Vendor
Itsourcecode
- Vendor
- CVE Published:
- 24 December 2025
Badges
What is CVE-2025-15073?
A SQL injection vulnerability exists within the itsourcecode Online Frozen Foods Ordering System version 1.0, specifically in the /contact_us.php file. This flaw allows an attacker to manipulate the Name argument, leading to potential unauthorized access to the database. The vulnerability can be exploited remotely, and details of the exploit have been publicly disclosed. Users of this system are advised to apply necessary patches and review their security measures to mitigate risks.
Affected Version(s)
Online Frozen Foods Ordering System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
