A weakness has been identified in code-projects Prison Management System 2.0. This issue affects some unknown processing of the file /admin/search.php. Executing manipulation of the argument keyname can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be exploited.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 17 Dec 2025 05:00:00 +0900

Type Values Removed Values Added
First Time appeared Carmelo
Carmelo prison Management System
CPEs cpe:2.3:a:carmelo:prison_management_system:2.0:*:*:*:*:*:*:*
Vendors & Products Carmelo
Carmelo prison Management System

Tue, 16 Dec 2025 02:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 15 Dec 2025 06:30:00 +0900

Type Values Removed Values Added
First Time appeared Code-projects
Code-projects prison Management System
Vendors & Products Code-projects
Code-projects prison Management System

Sat, 13 Dec 2025 19:45:00 +0900

Type Values Removed Values Added
Description A weakness has been identified in code-projects Prison Management System 2.0. This issue affects some unknown processing of the file /admin/search.php. Executing manipulation of the argument keyname can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be exploited.
Title code-projects Prison Management System search.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-12-15T16:45:27.497Z

Reserved: 2025-12-12T15:11:52.831Z

Link: CVE-2025-14589

cve-icon Vulnrichment

Updated: 2025-12-15T16:45:24.179Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-13T16:16:52.293

Modified: 2025-12-16T19:53:06.057

Link: CVE-2025-14589

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-15T06:14:35Z

Weaknesses