VulnerabilityAnalyzed
CVE-2025-4038
A vulnerability was found in code-projects Train Ticket Reservation System 1.0.
MEDIUM 4.8EPSS 0.30%
Does this matter?
Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in code-projects Train Ticket Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is the function Reservation of the component Ticket Reservation. The manipulation of the argument Name leads to stack-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
- CVSS 4.0
- 4.8 MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.30% probability · 23th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119, CWE-121, CWE-787
- Affected
- fabian/train ticket reservation system
- Source
- cna@vuldb.com
References
- https://code-projects.org/Product
- https://github.com/zzzxc643/cve/blob/main/Buffer%20Overflow%20Vulnerability%20in%20Train%20Reservation%20System.mdExploit
- https://vuldb.com/?ctiid.306403Permissions Required, VDB Entry
- https://vuldb.com/?id.306403Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.559344Third Party Advisory, VDB Entry
- https://github.com/zzzxc643/cve/blob/main/Buffer%20Overflow%20Vulnerability%20in%20Train%20Reservation%20System.mdExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.