Vulnerability Description
A security vulnerability has been detected in SourceCodester Inventory Management System 1.0. The affected element is an unknown function of the component SVC Report Export. Such manipulation leads to csv injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Warren-Daloyan | Inventory Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://vuldb.com/?ctiid.334671Permissions RequiredVDB Entry
- https://vuldb.com/?id.334671Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.702119Third Party AdvisoryVDB Entry
- https://www.notion.so/Spreadsheet-Formula-Injection-Leading-to-Remote-Code-ExecuExploitMitigationThird Party Advisory
- https://www.sourcecodester.com/Product
FAQ
What is CVE-2025-14229?
CVE-2025-14229 is a vulnerability with a CVSS score of 4.7 (MEDIUM). A security vulnerability has been detected in SourceCodester Inventory Management System 1.0. The affected element is an unknown function of the component SVC Report Export. Such manipulation leads to...
How severe is CVE-2025-14229?
CVE-2025-14229 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-14229?
Check the references section above for vendor advisories and patch information. Affected products include: Warren-Daloyan Inventory Management System.