A weakness has been identified in code-projects Prison Management System 2.0. This issue affects some unknown processing of the file /admin/search.php. Executing a manipulation of the argument keyname can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
History

Tue, 24 Feb 2026 06:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in code-projects Prison Management System 2.0. This issue affects some unknown processing of the file /admin/search.php. Executing manipulation of the argument keyname can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be exploited. A weakness has been identified in code-projects Prison Management System 2.0. This issue affects some unknown processing of the file /admin/search.php. Executing a manipulation of the argument keyname can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
CPEs cpe:2.3:a:code-projects:prison_management_system:*:*:*:*:*:*:*:*

Tue, 16 Dec 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Carmelo
Carmelo prison Management System
CPEs cpe:2.3:a:carmelo:prison_management_system:2.0:*:*:*:*:*:*:*
Vendors & Products Carmelo
Carmelo prison Management System

Mon, 15 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 14 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Code-projects
Code-projects prison Management System
Vendors & Products Code-projects
Code-projects prison Management System

Sat, 13 Dec 2025 10:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in code-projects Prison Management System 2.0. This issue affects some unknown processing of the file /admin/search.php. Executing manipulation of the argument keyname can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be exploited.
Title code-projects Prison Management System search.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-12-13T10:32:07.091Z

Updated: 2026-02-24T05:48:41.011Z

Reserved: 2025-12-12T15:11:52.831Z

Link: CVE-2025-14589

cve-icon Vulnrichment

Updated: 2025-12-15T16:45:24.179Z

cve-icon NVD

Status : Modified

Published: 2025-12-13T16:16:52.293

Modified: 2026-02-24T06:16:23.533

Link: CVE-2025-14589

cve-icon Redhat

No data.