PT-2025-18179 · Unknown · Code-Projects Product Management System

·

CVE-2025-4069

·

Published

2025-04-29

·

Updated

2025-04-29

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Product Management System version 1.0
Description A critical issue has been found in the function add item. The manipulation of the argument st.productname leads to a stack-based buffer overflow. This issue can be exploited locally.
Recommendations For code-projects Product Management System version 1.0, as a temporary workaround, consider disabling the add item function until a patch is available. Restrict access to the add item function to minimize the risk of exploitation. Avoid using the argument st.productname in the affected function until the issue is resolved.

Exploit

Fix

Stack Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-4069

Affected Products

Code-Projects Product Management System