VulnerabilityAnalyzed
CVE-2025-8928
A vulnerability was identified in code-projects Medical Store Management System 1.0.
LOW 2.1EPSS 0.39%
Does this matter?
Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was identified in code-projects Medical Store Management System 1.0. This affects an unknown part of the file UpdateMedicines.java of the component Update Medicines Page. The manipulation of the argument productNameTxt leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.39% probability · 33th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-89
- Affected
- fabian/medical store management system
- Source
- cna@vuldb.com
References
- https://code-projects.org/Product
- https://vuldb.com/?ctiid.319887Permissions Required, VDB Entry
- https://vuldb.com/?id.319887Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.631661Third Party Advisory, VDB Entry
- https://www.yuque.com/gongzi-jsnek/xb2q3a/ktz2n3ywyt85zct3#vulnerability-details-and-pocExploit, Third Party Advisory
- https://www.yuque.com/gongzi-jsnek/xb2q3a/ktz2n3ywyt85zct3?singleDocExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.