CVE-2025-3141

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Apr 3, 2025
Updated: Apr 9, 2025
CWE ID 79

Summary

CVE-2025-3141 is a critical vulnerability identified in the SourceCodester Online Medicine Ordering System 1.0. The issue lies within unknown code in the file /manage_category.php, allowing for sql injection attacks. By manipulating the ID argument, an attacker can remotely execute malicious SQL commands, potentially gaining unauthorized access or data theft. This vulnerability has been disclosed to the public, increasing the risk of exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share