---
id: CVE-2025-14666
title: A weakness has been identified in itsourcecode COVID Tracking System 1.0
summary: >-
  A weakness has been identified in itsourcecode COVID Tracking System 1.0. The
  affected element is an unknown function of the file /admin/?page=user. This
  manipulation of the argument Username causes sql injection. The attack is
  possible …
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
  - CWE-89
vendor: angeljudesuarez
product: covid_tracking_system
affected:
  - covid_tracking_system = 1.0
published: '2025-12-14'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T10:10:00.473'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14666'
references:
  - url: 'https://github.com/bardminx/Lonlydance/issues/2'
    label: cna@vuldb.com
  - url: 'https://itsourcecode.com/'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.336398'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.336398'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.714786'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00387
epssPercentile: 0.3021
ingestedAt: '2026-09-28T11:08:06.659Z'
---

## Overview

A weakness has been identified in itsourcecode COVID Tracking System 1.0. The affected element is an unknown function of the file /admin/?page=user. This manipulation of the argument Username causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

## Affected

- `covid_tracking_system = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
