CVE-2025-14833

A security flaw has been discovered in code-projects Online Appointment Booking System 1.0. The impacted element is an unknown function of the file /admin/deletemanagerclinic.php. Performing manipulation of the argument clinic results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be exploited.
References
Link Resource
https://code-projects.org/ Product
https://github.com/Sqli22/Sqli/issues/2 Issue Tracking
https://vuldb.com/?ctiid.336982 Permissions Required VDB Entry
https://vuldb.com/?id.336982 Third Party Advisory VDB Entry
https://vuldb.com/?submit.715073 Third Party Advisory VDB Entry
https://github.com/Sqli22/Sqli/issues/2 Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:anisha:online_appointment_booking_system:1.0:*:*:*:*:*:*:*

History

18 Dec 2025, 19:37

Type Values Removed Values Added
First Time Anisha
Anisha online Appointment Booking System
CPE cpe:2.3:a:anisha:online_appointment_booking_system:1.0:*:*:*:*:*:*:*
References () https://code-projects.org/ - () https://code-projects.org/ - Product
References () https://github.com/Sqli22/Sqli/issues/2 - () https://github.com/Sqli22/Sqli/issues/2 - Issue Tracking
References () https://vuldb.com/?ctiid.336982 - () https://vuldb.com/?ctiid.336982 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.336982 - () https://vuldb.com/?id.336982 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.715073 - () https://vuldb.com/?submit.715073 - Third Party Advisory, VDB Entry

18 Dec 2025, 15:15

Type Values Removed Values Added
References () https://github.com/Sqli22/Sqli/issues/2 - () https://github.com/Sqli22/Sqli/issues/2 -

17 Dec 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-17 23:15

Updated : 2025-12-18 19:37


NVD link : CVE-2025-14833

Mitre link : CVE-2025-14833

CVE.ORG link : CVE-2025-14833


JSON object : View

Products Affected

anisha

  • online_appointment_booking_system
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')