CVE-2025-14229

MEDIUM

SourceCodester Inventory Management System 1.0 - Code Injection

Title source: llm

Description

A security vulnerability has been detected in SourceCodester Inventory Management System 1.0. The affected element is an unknown function of the component SVC Report Export. Such manipulation leads to csv injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

Scores

CVSS v3 4.7
EPSS 0.0005
EPSS Percentile 15.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-74 CWE-1236
Status published

Affected Products (1)

warren-daloyan/inventory_management_system

Timeline

Published Dec 08, 2025
Tracked Since Feb 18, 2026