
🚨 HIGH: CVE-2025-15186 (CVSS 7.3) - SQL Injection in Refugee Food Management System 1.0 via /home/addusers[.]php. Remotely exploitable, public exploit available. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/4fzg7NmKgZ
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
A vulnerability has been found in code-projects Refugee Food Management System 1.0. Affected by this issue is some unknown functionality of the file /home/addusers.php. Such manipulation of the argument a leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
NONE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.
1 version affected across 1 product

🚨 HIGH: CVE-2025-15186 (CVSS 7.3) - SQL Injection in Refugee Food Management System 1.0 via /home/addusers[.]php. Remotely exploitable, public exploit available. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/4fzg7NmKgZ
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | fabian | refugee_food_management_system | 1.0 | - | - |