CVE-2025-14230

⚪ Do wiadomości

Wstrzyknięcie SQL w Daily Time Recording System umożliwia zdalne wykonanie ataku.

CVSS
6.3
EPSS
0.3%
Exploit
poc
Vendor
carmelo
Opis źródłowy (NVD)

A vulnerability was detected in code-projects Daily Time Recording System 4.5.0. The impacted element is an unknown function of the file /admin/add_payroll.php. Performing manipulation of the argument detail_Id results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.

exploit sql-injection Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2025-12-08 12:16:02 UTC
Ostatnia modyfikacja (NVD)2026-10-07 20:10:01 UTC
Referencje