
🚨 HIGH: CVE-2025-14637 (CVSS 7.3) - SQL Injection in itsourcecode Online Pet Shop Management System 1.0. Remotely exploitable via /pet1/addcnp[.]php. Public exploit available. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/KMt2J8wGPT
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
A weakness has been identified in itsourcecode Online Pet Shop Management System 1.0. This vulnerability affects unknown code of the file /pet1/addcnp.php. This manipulation of the argument cnpname causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
NONE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.
1 version affected across 1 product

🚨 HIGH: CVE-2025-14637 (CVSS 7.3) - SQL Injection in itsourcecode Online Pet Shop Management System 1.0. Remotely exploitable via /pet1/addcnp[.]php. Public exploit available. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/KMt2J8wGPT
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | facebook-riares | online_pet_shop_management_system | 1.0 | - | - |