A vulnerability was determined in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /contact_us.php. This manipulation of the argument Name causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
itsourcecode Online Frozen Foods Ordering System contact_us.php sql injection
Problem type
Affected products
itsourcecode
1.0 - AFFECTED
References
https://vuldb.com/?id.338330
https://vuldb.com/?ctiid.338330
https://vuldb.com/?submit.721321
https://github.com/24ggee/CVE/issues/1
https://itsourcecode.com/
GitHub Security Advisories
GHSA-2h4c-6rjw-w7rh
A vulnerability was determined in itsourcecode Online Frozen Foods Ordering System 1.0. This...
https://github.com/advisories/GHSA-2h4c-6rjw-w7rhA vulnerability was determined in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /contact_us.php. This manipulation of the argument Name causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
https://nvd.nist.gov/vuln/detail/CVE-2025-15073
https://github.com/24ggee/CVE/issues/1
https://itsourcecode.com
https://vuldb.com/?ctiid.338330
https://vuldb.com/?id.338330
https://vuldb.com/?submit.721321
https://github.com/advisories/GHSA-2h4c-6rjw-w7rh
JSON source
https://cveawg.mitre.org/api/cve/CVE-2025-15073Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2025-15073",
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"dateUpdated": "2025-12-26T16:35:30.166Z",
"dateReserved": "2025-12-24T16:48:17.013Z",
"datePublished": "2025-12-24T23:02:07.917Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB",
"dateUpdated": "2025-12-24T23:02:07.917Z"
},
"title": "itsourcecode Online Frozen Foods Ordering System contact_us.php sql injection",
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /contact_us.php. This manipulation of the argument Name causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized."
}
],
"affected": [
{
"vendor": "itsourcecode",
"product": "Online Frozen Foods Ordering System",
"versions": [
{
"version": "1.0",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "SQL Injection",
"cweId": "CWE-89",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"lang": "en",
"description": "Injection",
"cweId": "CWE-74",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://vuldb.com/?id.338330",
"name": "VDB-338330 | itsourcecode Online Frozen Foods Ordering System contact_us.php sql injection",
"tags": [
"vdb-entry",
"technical-description"
]
},
{
"url": "https://vuldb.com/?ctiid.338330",
"name": "VDB-338330 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
]
},
{
"url": "https://vuldb.com/?submit.721321",
"name": "Submit #721321 | itsourcecode Online Frozen Foods Ordering System v1.0 SQL Injection",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://github.com/24ggee/CVE/issues/1",
"tags": [
"exploit",
"issue-tracking"
]
},
{
"url": "https://itsourcecode.com/",
"tags": [
"product"
]
}
],
"metrics": [
{},
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"baseScore": 7.3,
"baseSeverity": "HIGH"
}
},
{
"cvssV3_0": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"baseScore": 7.3,
"baseSeverity": "HIGH"
}
},
{
"cvssV2_0": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"baseScore": 7.5
}
}
],
"timeline": [
{
"time": "2025-12-24T00:00:00.000Z",
"lang": "en",
"value": "Advisory disclosed"
},
{
"time": "2025-12-24T01:00:00.000Z",
"lang": "en",
"value": "VulDB entry created"
},
{
"time": "2025-12-24T17:53:27.000Z",
"lang": "en",
"value": "VulDB entry last update"
}
],
"credits": [
{
"lang": "en",
"value": "Seven7. (VulDB User)",
"type": "reporter"
}
],
"tags": [
"x_freeware"
]
},
"adp": [
{
"providerMetadata": {
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP",
"dateUpdated": "2025-12-26T16:35:30.166Z"
},
"title": "CISA ADP Vulnrichment",
"metrics": [
{}
]
}
]
}
}