---
id: CVE-2025-14229
title: >-
  A security vulnerability has been detected in SourceCodester Inventory
  Management System 1.0
summary: >-
  A security vulnerability has been detected in SourceCodester Inventory
  Management System 1.0. The affected element is an unknown function of the
  component SVC Report Export. Such manipulation leads to csv injection. It is
  possible to lau…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-1236
  - CWE-1236
vendor: warren-daloyan
product: inventory_management_system
affected:
  - inventory_management_system = 1.0
published: '2025-12-08'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14229'
references:
  - url: 'https://vuldb.com/?ctiid.334671'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.334671'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.702119'
    label: cna@vuldb.com
  - url: >-
      https://www.notion.so/Spreadsheet-Formula-Injection-Leading-to-Remote-Code-Execution-in-SourceCodester-Inventory-Managemen-2b723917db8c80dfaaabe2b74d6f283d?source=copy_link
    label: cna@vuldb.com
  - url: 'https://www.sourcecodester.com/'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00351
epssPercentile: 0.26521
ingestedAt: '2026-10-07T20:46:46.763Z'
---

## Overview

A security vulnerability has been detected in SourceCodester Inventory Management System 1.0. The affected element is an unknown function of the component SVC Report Export. Such manipulation leads to csv injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

## Affected

- `inventory_management_system = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
