PT-2025-14884 · Sourcecodester · Sourcecodester Web-Based Pharmacy Product Management System

Puppy_6S6

·

Published

2025-04-04

·

Updated

2025-05-14

·

CVE-2025-3244

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Web-based Pharmacy Product Management System version 1.0
Description A critical vulnerability was found in the SourceCodester Web-based Pharmacy Product Management System. The issue affects an unknown functionality of the file /add-admin.php of the component Create User Page. The manipulation of the Avatar argument leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Recommendations For SourceCodester Web-based Pharmacy Product Management System version 1.0, as a temporary workaround, consider disabling the /add-admin.php file or restricting access to it until a patch is available. Avoid using the Avatar argument in the affected Create User Page until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-3244

Affected Products

Sourcecodester Web-Based Pharmacy Product Management System