---
id: CVE-2025-14251
title: >-
  A security vulnerability has been detected in code-projects Online Ordering
  System 1.0
summary: >-
  A security vulnerability has been detected in code-projects Online Ordering
  System 1.0. This affects an unknown function of the file /admin/ of the
  component Admin Login. Such manipulation of the argument Username leads to sql
  injection.…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
  - CWE-89
vendor: fabian
product: online_ordering_system
affected:
  - online_ordering_system = 1.0
published: '2025-12-08'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14251'
references:
  - url: 'https://code-projects.org/'
    label: cna@vuldb.com
  - url: 'https://github.com/zzb1388/cve/issues/95'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.334761'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.334761'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.702467'
    label: cna@vuldb.com
  - url: 'https://github.com/zzb1388/cve/issues/95'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00387
epssPercentile: 0.30592
ingestedAt: '2026-10-07T20:46:46.765Z'
---

## Overview

A security vulnerability has been detected in code-projects Online Ordering System 1.0. This affects an unknown function of the file /admin/ of the component Admin Login. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

## Affected

- `online_ordering_system = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
