---
id: CVE-2025-14531
title: A vulnerability was found in code-projects Rental Management System 2.0
summary: >-
  A vulnerability was found in code-projects Rental Management System 2.0. This
  affects an unknown function of the file Transaction.java of the component Log
  Handler. Performing manipulation results in crlf injection. The attack can be
  ini…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-74
  - CWE-93
vendor: carmelo
product: rental_management_system
affected:
  - rental_management_system = 2.0
published: '2025-12-11'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14531'
references:
  - url: 'https://code-projects.org/'
    label: cna@vuldb.com
  - url: 'https://github.com/asd1238525/cve/blob/main/CRLF.md'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.335872'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.335872'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.703239'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00321
epssPercentile: 0.23012
ingestedAt: '2026-10-07T20:46:46.858Z'
---

## Overview

A vulnerability was found in code-projects Rental Management System 2.0. This affects an unknown function of the file Transaction.java of the component Log Handler. Performing manipulation results in crlf injection. The attack can be initiated remotely. The exploit has been made public and could be used.

## Affected

- `rental_management_system = 2.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
