CVE-2025-3783
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Apr 18, 2025
Updated: Apr 23, 2025
CWE ID 416
Summary
CVE-2025-3783 is a critical vulnerability identified in the SourceCodester Web-based Pharmacy Product Management System version 1.0. This issue affects an unspecified functionality of the file /add-product.php. An attacker can exploit this vulnerability by manipulating the Avatar argument, resulting in unrestricted file uploads. The attack can be executed remotely, and the exploit for this vulnerability has been made public, increasing the risk for potential exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.