CVE-2025-15182CRITICAL 7.3EPSS p29.1%
CVE-2025-15182CVE-2025-15182
fabian / refugee_food_management_system
Description
A weakness has been identified in code-projects Refugee Food Management System 1.0. This affects an unknown function of the file /home/served.php. Executing manipulation of the argument refNo can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.
Scoring
| CVSS 3.1 | 7.3 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
| EPSS | 0.37% probability of exploitation · percentile 29.1% · 2026-10-05T12:00:23Z |
| Published | 2025-12-29 |
| Last modified | 2026-10-05 |
Underlying weaknesses· 2
References
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-74 | 0% | live |
| Weakness | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')cwe-89 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.