CVE-2025-3825
CVSS 3.1 Score 4.1 of 10 (medium)
Details
Summary
CVE-2025-3825 is a recently disclosed vulnerability affecting the SourceCodester Web-based Pharmacy Product Management System 1.0. This issue is classified as problematic due to the presence of a cross-site scripting (XSS) vulnerability. Specifically, an unknown functionality in the file add-category.php is at risk. Manipulation of the argument txtcategory_name can lead to the execution of malicious scripts in users' browsers. Since this vulnerability can be exploited remotely, it poses a significant threat to the security of systems using this product management system. It is strongly advised that users apply the necessary patches as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.