CVE-2025-3825

CVSS 3.1 Score 4.1 of 10 (medium)

Details

Published Apr 20, 2025
Updated: Apr 30, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-3825 is a recently disclosed vulnerability affecting the SourceCodester Web-based Pharmacy Product Management System 1.0. This issue is classified as problematic due to the presence of a cross-site scripting (XSS) vulnerability. Specifically, an unknown functionality in the file add-category.php is at risk. Manipulation of the argument txtcategory_name can lead to the execution of malicious scripts in users' browsers. Since this vulnerability can be exploited remotely, it poses a significant threat to the security of systems using this product management system. It is strongly advised that users apply the necessary patches as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share