CVE-2025-14567 describes a missing authentication vulnerability in haxxorsid Stock-Management-System, specifically affecting an unknown function within the /api/employees file in versions up to fbbbf213e9c93b87183a3891f77e3cc7095f22b0. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating it can be exploited remotely with low attack complexity, potentially leading to high confidentiality impact without requiring user interaction. While exploit code has been publicly released, there is no evidence of active exploitation, and it has garnered minimal community discussion or media coverage. Importantly, this vulnerability only impacts unsupported versions of the product.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2018-01-27CPE matchmatch criteria | cpe:2.3:a:haxxorsid:stock-management-system:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.