CVE-2025-15183

A security vulnerability has been detected in code-projects Refugee Food Management System 1.0. This impacts an unknown function of the file /home/viewtakenfd.php. The manipulation of the argument tfid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
References
Link Resource
https://code-projects.org/ Product
https://github.com/ctg503/CVE/issues/3 Permissions Required VDB Entry
https://vuldb.com/?ctiid.338568 Third Party Advisory VDB Entry
https://vuldb.com/?id.338568 Third Party Advisory VDB Entry
https://vuldb.com/?submit.721273 Third Party Advisory VDB Entry
https://vuldb.com/?submit.722808 Third Party Advisory VDB Entry
https://vuldb.com/?submit.722809 Third Party Advisory VDB Entry
https://vuldb.com/?submit.722810 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:fabian:refugee_food_management_system:1.0:*:*:*:*:*:*:*

History

30 Dec 2025, 21:11

Type Values Removed Values Added
References () https://code-projects.org/ - () https://code-projects.org/ - Product
References () https://github.com/ctg503/CVE/issues/3 - () https://github.com/ctg503/CVE/issues/3 - Permissions Required, VDB Entry
References () https://vuldb.com/?ctiid.338568 - () https://vuldb.com/?ctiid.338568 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?id.338568 - () https://vuldb.com/?id.338568 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.721273 - () https://vuldb.com/?submit.721273 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.722808 - () https://vuldb.com/?submit.722808 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.722809 - () https://vuldb.com/?submit.722809 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.722810 - () https://vuldb.com/?submit.722810 - Third Party Advisory, VDB Entry
First Time Fabian
Fabian refugee Food Management System
CPE cpe:2.3:a:fabian:refugee_food_management_system:1.0:*:*:*:*:*:*:*

29 Dec 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-29 10:15

Updated : 2025-12-30 21:11


NVD link : CVE-2025-15183

Mitre link : CVE-2025-15183

CVE.ORG link : CVE-2025-15183


JSON object : View

Products Affected

fabian

  • refugee_food_management_system
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')